SAP disclosed CVE-2026-44747, a critical memory corruption vulnerability in SAP NetWeaver Application Server ABAP, and published remediation guidance in Security Note 3747367 as part of its Security Patch Day materials. The flaw is classified as CWE-787 and affects multiple SAP ABAP kernel releases, including KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, and 9.16 through 9.20.
The vulnerability can be exploited remotely by an authenticated attacker with low privileges and carries a CVSS v3.1 score of 9.1 (AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Successful exploitation could cause unauthorized data access, data modification, privilege escalation, or system unavailability. Public reporting said there was no confirmed active exploitation at the time of disclosure, but the impact profile makes patching affected SAP environments a priority.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
SAP released its July 2026 Security Patch Day updates, publishing 16 new security notes, one GitHub security advisory, and three updates to previously released notes. The release highlighted CVE-2026-44747 in SAP NetWeaver Application Server ABAP as the most severe issue and also called out critical flaws in SAP Approuter and SAP Commerce Cloud.
CVE-2026-44747 was recorded on July 14, 2026 as a memory corruption flaw in SAP NetWeaver Application Server ABAP. The vulnerability was classified as CWE-787 and described as allowing an authenticated attacker to cause unauthorized data access, modification, or system unavailability.
SAP released Security Note 3747367 to remediate a memory corruption vulnerability in SAP NetWeaver Application Server ABAP. The note is referenced from SAP's May 2026 Security Patch Day materials.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
15 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcethehackernews.com
Open sourcethecybersecguru.com
Open sourcesecurityweek.com
Open sourcecvefeed.io
Open sourceurl.sap
Open sourcecisa.gov
Open sourceme.sap.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.