Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.
July 2026 Notes
Monthly Summary and Highlights
This month, the total number was 20 notes (16 new, 1 security advisory and 3 updates), 5 more than in June. This month, 4 Hot News were published, the same number as in the previous period. As for high criticality notes, there are 6, four more compared to June. Medium and low notes will not be reviewed, so we will detail a total of 10 notes (all with a CVSS of 7 or higher).
We have a total of 20 notes for the month (16 new, 1 security advisory and 3 updates to notes from previous months).
We will review in detail a total of 10 notes, all of high criticality and Hot News:
-
The highest criticality note of the month (CVSS 9.9) is a Hot News and is related to “Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP”.
-
The second highest criticality note (CVSS 9.1) is another Hot News and is related to “HTTP Request Smuggling in SAP Approuter”.
-
The third note with the same criticality (CVSS 9.1) is another Hot News and is related to “Insecure Sample Credentials in SAP Commerce Cloud”.
-
The fourth highest criticality note (CVSS 9.0) is the last Hot News of the month and is related to “Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)”.
-
The fifth note we will review (CVSS 8.8) is of high criticality and deals with “Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell)”.
-
The sixth note we will review (CVSS 8.4) is of high criticality and deals with “DLL Hijacking vulnerability in SAProuter on Microsoft Windows”.
-
The seventh note we will review (CVSS 8.2) is of high criticality and deals with “Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)”.
-
The eighth note we will review (CVSS 8.1) is of high criticality and deals with “Open Redirect vulnerability in SAP Approuter”.
-
The ninth note with the same criticality (CVSS 8.1) is of high criticality and deals with “Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud”.
-
The tenth and last note we will review (CVSS 7.6) is of high criticality and deals with “Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)”.
This month, the most predominant type has been “Cross-Site Scripting (XSS)” (3/20 in the patch day).
In the chart, we can see the classification of July’s notes, as well as the evolution and classification of the previous 5 months (only Sec. Tuesday / Patch Day notes – by SAP):
Full details
The full details of the most relevant notes are as follows (in English):
-
Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP (3747367): SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorised data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 9.9/10 [CVE-2026-44747]
-
HTTP Request Smuggling in SAP Approuter (3720138): Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronisation. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability. CVSS v3 Base Score 9.1/10 [CVE-2026-27690]
-
Insecure Sample Credentials in SAP Commerce Cloud (3753495): SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability. A temporary workaround is available. CVSS v3 Base Score 9.1/10 [CVE-2026-44761]
-
Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) (3727078): SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable. CVSS v3 Base Score 9.0/10 [CVE-2026-40128]
-
Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell) (3758101): This Security note addresses multiple known vulnerabilities in Apache Camel within SAP Integration Suite. These issues impact message-based header injection and deserialisation mechanisms in camel mail and JMS components, allowing attackers to achieve remote code execution and arbitrary file writes on downstream components. It has a high impact on confidentiality, integrity and availability of the application. A temporary workaround is available. CVSS v3 Base Score 8.8/10 [CVE-2026-40860, CVE-2026-40453, CVE-2026-33454]
-
DLL Hijacking vulnerability in SAProuter on Microsoft Windows (3692165): SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system. CVSS v3 Base Score 8.4/10 [CVE-2026-0487]
-
Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard) (3748227): SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user’s browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client’s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application. A temporary workaround is available. CVSS v3 Base Score 8.2/10 [CVE-2026-44752]
-
Open Redirect vulnerability in SAP Approuter (3741519): SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorised access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application. A temporary workaround is available. CVSS v3 Base Score 8.1/10 [CVE-2026-44745]
-
Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud (3763800): This Security Note addresses multiple known vulnerabilities in Apache Tomcat used by SAP Commerce Cloud. Remote unauthenticated attackers could exploit these vulnerabilities to bypass authentication, send crafted HTTP/2 requests, or bypass authorisation rules, potentially resulting in a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 8.1/10 [CVE-2026-43512, CVE-2026-41293, CVE-2026-43515]
-
Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud (3763800): This Security Note addresses multiple known vulnerabilities in Apache Tomcat used by SAP Commerce Cloud. Remote unauthenticated attackers could exploit these vulnerabilities to bypass authentication, send crafted HTTP/2 requests, or bypass authorisation rules, potentially resulting in a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 8.1/10 [CVE-2026-43512, CVE-2026-41293, CVE-2026-43515]
-
Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach) (3773304): SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application’s library, can trigger insecure deserialisation and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system. CVSS v3 Base Score 7.6/10 [CVE-2026-58233]
Reference links
References, in English, from SAP and Onapsis:
Affected resources
The full list of affected systems/components is as follows:
-
SAP NetWeaver Application Server ABAP: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20
-
SAP Approuter: SAP Approuter node.js package < 21.2.0
-
SAP Commerce Cloud: HY_COM 2205, COM_CLOUD 2211, 2211-JDK21
-
SAP NetWeaver Application Server Java (Web Container): ENGINEAPI 7.50
-
SAP Integration Suite (Edge Integration Cell): SAP Integration Suite (Edge Integration Cell) < 8.43.11
-
SAProuter on Microsoft Windows: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, SAP_ROUTER 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.17, 9.18
-
SAP NetWeaver Application Server Java(Configuration Wizard): LMCTC 7.50
-
SAP Change and Transport System Attach Tool (ctsattach): CTS_UPLOAD_CLT 1




