{"id":14570,"date":"2026-07-20T10:28:04","date_gmt":"2026-07-20T08:28:04","guid":{"rendered":"https:\/\/www.inprosec.com\/?p=14570"},"modified":"2026-07-20T10:28:04","modified_gmt":"2026-07-20T08:28:04","slug":"sap-security-notes-july-2026","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/","title":{"rendered":"SAP Security Notes, July 2026"},"content":{"rendered":"<p><b>Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.<\/b><\/p>\n\n<h2>July 2026 Notes<\/h2>\n<h3>Monthly Summary and Highlights<\/h3>\n<div>\n<div class=\"elementToProof\">\n<div class=\"elementToProof\">\n<div class=\"elementToProof\">\n<div class=\"elementToProof\">\n<div class=\"elementToProof\">\n<div class=\"elementToProof\">\n<div class=\"elementToProof\">This month, the total number was <b>20 notes<\/b> (16 new, 1 security advisory and 3 updates), 5 more than in June. This month, 4 Hot News were published, the same number as in the previous period. As for high criticality notes, there are 6, four more compared to June. Medium and low notes will not be reviewed, so we will detail a total of <b>10 notes<\/b> (all with a CVSS of 7 or higher).<\/div>\n<div class=\"elementToProof\">We have a total of <b>20 notes<\/b> for the month (16 new, 1 security advisory and 3 updates to notes from previous months).<\/div>\n<div class=\"elementToProof\">We will review in detail a total of 10 notes, all of high criticality and Hot News:<\/div>\n<div><\/div>\n<ol start=\"1\" data-path-to-node=\"9\">\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The highest criticality note of the month (<b>CVSS <\/b><span style=\"color: #ff0000;\"><b>9.9<\/b><\/span>) is a Hot News and is related to <b>&#8220;Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The second highest criticality note (<b>CVSS <\/b><span style=\"color: #ff0000;\"><b>9.1<\/b><\/span>) is another Hot News and is related to <b>&#8220;HTTP Request Smuggling in SAP Approuter&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The third note with the same criticality (<b>CVSS <\/b><span style=\"color: #ff0000;\"><b>9.1<\/b><\/span>) is another Hot News and is related to <b>&#8220;Insecure Sample Credentials in SAP Commerce Cloud&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The fourth highest criticality note (<b>CVSS <\/b><span style=\"color: #ff0000;\"><b>9.0<\/b><\/span>) is the last Hot News of the month and is related to <b>&#8220;Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The fifth note we will review (<b>CVSS <\/b><span style=\"color: #ffcc00;\"><b>8.8<\/b><\/span>) is of high criticality and deals with <b>&#8220;Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The sixth note we will review (<b>CVSS <\/b><span style=\"color: #ffcc00;\"><b>8.4<\/b><\/span>) is of high criticality and deals with <b>&#8220;DLL Hijacking vulnerability in SAProuter on Microsoft Windows&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The seventh note we will review (<b>CVSS <\/b><span style=\"color: #ffcc00;\"><b>8.2<\/b><\/span>) is of high criticality and deals with <b>&#8220;Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The eighth note we will review (<b>CVSS <\/b><span style=\"color: #ffcc00;\"><b>8.1<\/b><\/span>) is of high criticality and deals with <b>&#8220;Open Redirect vulnerability in SAP Approuter&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The ninth note with the same criticality (<b>CVSS <\/b><span style=\"color: #ffcc00;\"><b>8.1<\/b><\/span>) is of high criticality and deals with <b>&#8220;Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The tenth and last note we will review (<b>CVSS <\/b><span style=\"color: #ffcc00;\"><b>7.6<\/b><\/span>) is of high criticality and deals with <b>&#8220;Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)&#8221;<\/b>.<\/div>\n<div class=\"elementToProof\" role=\"presentation\"><\/div>\n<\/li>\n<\/ol>\n<div class=\"elementToProof\">This month, the most predominant type has been <b>&#8220;Cross-Site Scripting (XSS)&#8221;<\/b> (3\/20 in the patch day).<\/div>\n<div class=\"elementToProof\">In the chart, we can see the classification of July&#8217;s notes, as well as the evolution and classification of the previous 5 months (only Sec. Tuesday \/ Patch Day notes \u2013 by SAP):<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n<div><\/div>\n<\/div>\n<\/div>\n<p><img decoding=\"async\" class=\"aligncenter size-full wp-image-14572\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg\" alt=\"\" width=\"1200\" height=\"630\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg 1200w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP-300x158.jpg 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP-1024x538.jpg 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP-600x315.jpg 600w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" \/><\/p>\n<h2>Full details<\/h2>\n<p class=\"elementToProof\">The <b>full details of the most relevant notes<\/b> are as follows (in English):<\/p>\n<ol>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP (<\/b><a id=\"OWA9014d080-f5d0-556f-6464-381e575f9411\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3747367\" href=\"https:\/\/me.sap.com\/notes\/3747367\" data-auth=\"NotApplicable\" data-linkindex=\"0\"><b>3747367<\/b><\/a><b>)<\/b>: SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorised data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span style=\"color: #ff0000;\"><b>9.9<\/b><\/span><b>\/10 [<\/b><a id=\"OWA284287f5-d7cb-7a87-7a3d-0fbdb433c678\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44747\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44747\" data-auth=\"NotApplicable\" data-linkindex=\"1\"><b>CVE-2026-44747<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>HTTP Request Smuggling in SAP Approuter (<\/b><a id=\"OWAb3a76e3c-e438-d8b5-f495-5dfdbecb1711\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3720138\" href=\"https:\/\/me.sap.com\/notes\/3720138\" data-auth=\"NotApplicable\" data-linkindex=\"2\"><b>3720138<\/b><\/a><b>)<\/b>: Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronisation. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability. <b>CVSS v3 Base Score <\/b><span style=\"color: #ff0000;\"><b>9.1<\/b><\/span><b>\/10 [<\/b><a id=\"OWA0e0fcec2-fc4d-d88c-e17d-ae9fde8e3af2\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-27690\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-27690\" data-auth=\"NotApplicable\" data-linkindex=\"3\"><b>CVE-2026-27690<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Insecure Sample Credentials in SAP Commerce Cloud (<\/b><a id=\"OWA1798875b-9040-e1d3-a9cf-7ceec3d54532\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3753495\" href=\"https:\/\/me.sap.com\/notes\/3753495\" data-auth=\"NotApplicable\" data-linkindex=\"4\"><b>3753495<\/b><\/a><b>)<\/b>: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credentials originating from sample configuration provided in SAP Help Portal documentation. If left unchanged, an unauthenticated attacker could use these well-known credentials to obtain a valid access token and invoke certain APIs to read and modify data. Successful exploitation results in high impact on confidentiality and integrity, with no impact on availability. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span style=\"color: #ff0000;\"><b>9.1<\/b><\/span><b>\/10 [<\/b><a id=\"OWA19f792f0-39be-74eb-701e-4599ada9b9bb\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44761\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44761\" data-auth=\"NotApplicable\" data-linkindex=\"5\"><b>CVE-2026-44761<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) (<\/b><a id=\"OWA4e6b0b4a-636c-0f06-7c40-7d78ba8646c1\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3727078\" href=\"https:\/\/me.sap.com\/notes\/3727078\" data-auth=\"NotApplicable\" data-linkindex=\"6\"><b>3727078<\/b><\/a><b>)<\/b>: SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable. <b>CVSS v3 Base Score <\/b><span style=\"color: #ff0000;\"><b>9.0<\/b><\/span><b>\/10 [<\/b><a id=\"OWA564b7e30-b391-c719-a1c4-75b7c7f40a6d\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40128\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40128\" data-auth=\"NotApplicable\" data-linkindex=\"7\"><b>CVE-2026-40128<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell) (<\/b><a id=\"OWAbb163618-c298-9a6e-0968-34b1e42e9b47\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3758101\" href=\"https:\/\/me.sap.com\/notes\/3758101\" data-auth=\"NotApplicable\" data-linkindex=\"8\"><b>3758101<\/b><\/a><b>)<\/b>: This Security note addresses multiple known vulnerabilities in Apache Camel within SAP Integration Suite. These issues impact message-based header injection and deserialisation mechanisms in camel mail and JMS components, allowing attackers to achieve remote code execution and arbitrary file writes on downstream components. It has a high impact on confidentiality, integrity and availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span style=\"color: #ffcc00;\"><b>8.8<\/b><\/span><b>\/10 [<\/b><a id=\"OWA860a461c-8f34-f3c1-f4aa-2f3b9657c61a\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40860\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40860\" data-auth=\"NotApplicable\" data-linkindex=\"9\"><b>CVE-2026-40860<\/b><\/a><b>, <\/b><a id=\"OWAeb47b933-00a1-2155-ab38-d596b60a3a9e\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40453\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-40453\" data-auth=\"NotApplicable\" data-linkindex=\"10\"><b>CVE-2026-40453<\/b><\/a><b>, <\/b><a id=\"OWA0e03ec23-ae3c-34e9-d6a9-9d8499f014dc\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-33454\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-33454\" data-auth=\"NotApplicable\" data-linkindex=\"11\"><b>CVE-2026-33454<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>DLL Hijacking vulnerability in SAProuter on Microsoft Windows (<\/b><a id=\"OWA990e0839-7638-1c47-97a0-ab7e3f590a4f\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3692165\" href=\"https:\/\/me.sap.com\/notes\/3692165\" data-auth=\"NotApplicable\" data-linkindex=\"12\"><b>3692165<\/b><\/a><b>)<\/b>: SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system. <b>CVSS v3 Base Score <\/b><span style=\"color: #ffcc00;\"><b>8.4<\/b><\/span><b>\/10 [<\/b><a id=\"OWA9c117e4f-94a8-e66e-9954-760e234cbddf\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0487\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-0487\" data-auth=\"NotApplicable\" data-linkindex=\"13\"><b>CVE-2026-0487<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard) (<\/b><a id=\"OWA7aeca5f2-d3c7-a249-42dc-3b7663d7f30d\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3748227\" href=\"https:\/\/me.sap.com\/notes\/3748227\" data-auth=\"NotApplicable\" data-linkindex=\"14\"><b>3748227<\/b><\/a><b>)<\/b>: SAP NetWeaver Application Server Java allows an unauthenticated attacker to inject malicious JavaScript through crafted URLs. When a victim accesses such a URL, the script executes in the user&#8217;s browser, allowing the attacker to access sensitive session information and modify non-sensitive data displayed in the client&#8217;s browser. This results in a high impact on confidentiality, low impact on integrity with no impact on availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span style=\"color: #ffcc00;\"><b>8.2<\/b><\/span><b>\/10 [<\/b><a id=\"OWA43a98b9d-5ff9-adfa-4f63-a75dbed7579f\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44752\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44752\" data-auth=\"NotApplicable\" data-linkindex=\"15\"><b>CVE-2026-44752<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Open Redirect vulnerability in SAP Approuter (<\/b><a id=\"OWA5429ccc5-ad72-e4be-c62a-90faa5ae5528\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3741519\" href=\"https:\/\/me.sap.com\/notes\/3741519\" data-auth=\"NotApplicable\" data-linkindex=\"16\"><b>3741519<\/b><\/a><b>)<\/b>: SAP Approuter does not properly validate incoming request headers during the OAuth2 login flow under certain configurations. This allows an unauthenticated remote attacker to craft a malicious link which, when clicked by a victim, could lead to unauthorised access. Successful exploitation results in a high impact to the confidentiality and integrity with no impact on the availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span style=\"color: #ffcc00;\"><b>8.1<\/b><\/span><b>\/10 [<\/b><a id=\"OWA33078a24-07fc-d7ab-714b-9bca8d22a721\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44745\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44745\" data-auth=\"NotApplicable\" data-linkindex=\"17\"><b>CVE-2026-44745<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud (<\/b><a id=\"OWAc081fdd5-f56e-8453-5b88-cd9c5e9bdf01\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3763800\" href=\"https:\/\/me.sap.com\/notes\/3763800\" data-auth=\"NotApplicable\" data-linkindex=\"18\"><b>3763800<\/b><\/a><b>)<\/b>: This Security Note addresses multiple known vulnerabilities in Apache Tomcat used by SAP Commerce Cloud. Remote unauthenticated attackers could exploit these vulnerabilities to bypass authentication, send crafted HTTP\/2 requests, or bypass authorisation rules, potentially resulting in a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span style=\"color: #ffcc00;\"><b>8.1<\/b><\/span><b>\/10 [<\/b><a id=\"OWAea6f8303-1968-efea-1680-b68cbcbad824\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-43512\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-43512\" data-auth=\"NotApplicable\" data-linkindex=\"19\"><b>CVE-2026-43512<\/b><\/a><b>, <\/b><a id=\"OWAe2a98564-d28f-e4de-b2bc-6dbf77b32a08\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-41293\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-41293\" data-auth=\"NotApplicable\" data-linkindex=\"20\"><b>CVE-2026-41293<\/b><\/a><b>, <\/b><a id=\"OWAb3cd80e1-7880-9bbe-86ac-07ced00276b9\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-43515\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-43515\" data-auth=\"NotApplicable\" data-linkindex=\"21\"><b>CVE-2026-43515<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud (<\/b><a id=\"OWA6c3ab706-9982-2585-99ed-5085e4f9fc05\" class=\"OWAAutoLink\" title=\"https:\/\/www.google.com\/search?q=https:\/\/me.sap.com\/notes\/3763800\" href=\"https:\/\/www.google.com\/search?q=https:\/\/me.sap.com\/notes\/3763800\" rel=\"noopener\" data-auth=\"NotApplicable\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahcKEwiul4rPwdSVAxUAAAAAHQAAAAAQYw\" data-linkindex=\"22\"><b>3763800<\/b><\/a><b>): <\/b>This Security Note addresses multiple known vulnerabilities in Apache Tomcat used by SAP Commerce Cloud. Remote unauthenticated attackers could exploit these vulnerabilities to bypass authentication, send crafted HTTP\/2 requests, or bypass authorisation rules, potentially resulting in a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. <strong>CVSS v3 Base Score <span style=\"color: #ffcc00;\">8.1<\/span>\/10<\/strong><b> [<\/b><a id=\"OWA77312139-614a-946d-3f0f-1320d7bd2a60\" class=\"OWAAutoLink\" title=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43512\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43512\" rel=\"noopener\" data-auth=\"NotApplicable\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahcKEwiul4rPwdSVAxUAAAAAHQAAAAAQZA\" data-linkindex=\"23\"><b>CVE-2026-43512<\/b><\/a><b>, <\/b><a id=\"OWA9dad704e-920a-9ab4-7c44-b244cfc9a5dd\" class=\"OWAAutoLink\" title=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-41293\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-41293\" rel=\"noopener\" data-auth=\"NotApplicable\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahcKEwiul4rPwdSVAxUAAAAAHQAAAAAQZQ\" data-linkindex=\"24\"><b>CVE-2026-41293<\/b><\/a><b>, <\/b><a id=\"OWA10c26777-b650-de59-8917-f7365d7ce8dd\" class=\"OWAAutoLink\" title=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43515\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-43515\" rel=\"noopener\" data-auth=\"NotApplicable\" data-hveid=\"0\" data-ved=\"0CAAQ_4QMahcKEwiul4rPwdSVAxUAAAAAHQAAAAAQZg\" data-linkindex=\"25\"><b>CVE-2026-43515<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach) (<\/b><a id=\"OWA49311858-2ef3-8b6b-67b7-654b53f219da\" class=\"OWAAutoLink\" title=\"https:\/\/me.sap.com\/notes\/3773304\" href=\"https:\/\/me.sap.com\/notes\/3773304\" data-auth=\"NotApplicable\" data-linkindex=\"26\"><b>3773304<\/b><\/a><b>)<\/b>: SAP Change and Transport System Attach Tool (ctsattach) allows an authenticated attacker to supply a specially crafted archive file which, when processed by the application&#8217;s library, can trigger insecure deserialisation and lead to remote code execution (RCE) on the system. Successful exploitation requires a victim to process the malicious archive, enabling the attacker to execute the RCE and extract sensitive information and gain control over the system and its processes. This vulnerability has a high impact on confidentiality and integrity of the data, with a low impact on the availability of the system. <b>CVSS v3 Base Score <\/b><span style=\"color: #ffcc00;\"><b>7.6<\/b><\/span><b>\/10 [<\/b><a id=\"OWAd32de761-73fc-d434-7d07-fcf08bcbdf2b\" class=\"OWAAutoLink\" title=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58233\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58233\" data-auth=\"NotApplicable\" data-linkindex=\"27\"><b>CVE-2026-58233<\/b><\/a><b>]<\/b><\/div>\n<\/li>\n<\/ol>\n<p>&nbsp;<\/p>\n<p><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\">Reference links<\/strong><\/p>\n<div class=\"elementToProof\">References, in English, from SAP and Onapsis:<\/div>\n<ul data-path-to-node=\"22\">\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><a id=\"OWA35d8df02-b2fd-0c2b-3356-78f9fc9ccee5\" class=\"OWAAutoLink\" title=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/july-2026.html\" href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/july-2026.html\" data-auth=\"NotApplicable\" data-linkindex=\"28\">SAP Security Patch Day &#8211; July 2026<\/a><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><a id=\"OWAf523036f-ae2a-ef03-9088-cd14a7348378\" class=\"OWAAutoLink\" title=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-july-2026\/?_gl=1*1xahdag*_up*MQ..*_ga*MzgxNTMwMDMzLjE3ODQxMTI2Mjc.*_ga_2HEPRR6DH5*czE3ODQxMTI2MjckbzEkZzEkdDE3ODQxMTI2MzQkajUzJGwwJGg0NDEzODY0NDI.\" href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-july-2026\/?_gl=1*1xahdag*_up*MQ..*_ga*MzgxNTMwMDMzLjE3ODQxMTI2Mjc.*_ga_2HEPRR6DH5*czE3ODQxMTI2MjckbzEkZzEkdDE3ODQxMTI2MzQkajUzJGwwJGg0NDEzODY0NDI.\" data-auth=\"NotApplicable\" data-linkindex=\"29\">SAP Patch Day: July 2026 &#8211; Onapsis<\/a><\/div>\n<\/li>\n<\/ul>\n<h2><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\">Affected resources<\/strong><\/h2>\n<div>The full list of affected systems\/components is as follows:<\/div>\n<div><\/div>\n<ul>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver Application Server ABAP:<\/b> KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Approuter:<\/b> SAP Approuter node.js package &lt; 21.2.0<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Commerce Cloud:<\/b> HY_COM 2205, COM_CLOUD 2211, 2211-JDK21<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver Application Server Java (Web Container):<\/b> ENGINEAPI 7.50<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Integration Suite (Edge Integration Cell):<\/b> SAP Integration Suite (Edge Integration Cell) &lt; 8.43.11<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAProuter on Microsoft Windows:<\/b> KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, SAP_ROUTER 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.17, 9.18<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver Application Server Java(Configuration Wizard):<\/b> LMCTC 7.50<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Change and Transport System Attach Tool (ctsattach):<\/b> CTS_UPLOAD_CLT 1<\/div>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems. July 2026 Notes Monthly Summary and Highlights This month, the total number was 20 notes (16 new, 1 security advisory and 3 updates), 5 more than in June. This month, 4 Hot News were published,&#8230;<\/p>\n","protected":false},"author":6,"featured_media":14572,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[95,61],"tags":[150],"class_list":["post-14570","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-notes","category-sap-security-en-2","tag-sap-notes"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAP Security Notes, July 2026 - Inprosec<\/title>\n<meta name=\"description\" content=\"All updates to SAP systems notes from july 2026, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAP Security Notes, July 2026\" \/>\n<meta property=\"og:description\" content=\"All updates to SAP systems notes from july 2026, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2026-07-20T08:28:04+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"SAP Security Notes, July 2026\",\"datePublished\":\"2026-07-20T08:28:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/\"},\"wordCount\":1406,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Portada-Notas-SAP.jpg\",\"keywords\":[\"SAP Notes\"],\"articleSection\":[\"SAP Notes\",\"SAP Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/\",\"name\":\"SAP Security Notes, July 2026 - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Portada-Notas-SAP.jpg\",\"datePublished\":\"2026-07-20T08:28:04+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"description\":\"All updates to SAP systems notes from july 2026, to stay current and improve the security levels of your SAP systems.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Portada-Notas-SAP.jpg\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/07\\\/Portada-Notas-SAP.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-july-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAP Security Notes, July 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAP Security Notes, July 2026 - Inprosec","description":"All updates to SAP systems notes from july 2026, to stay current and improve the security levels of your SAP systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/","og_locale":"en_US","og_type":"article","og_title":"SAP Security Notes, July 2026","og_description":"All updates to SAP systems notes from july 2026, to stay current and improve the security levels of your SAP systems.","og_url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/","og_site_name":"Inprosec","article_published_time":"2026-07-20T08:28:04+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg","type":"image\/jpeg"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"SAP Security Notes, July 2026","datePublished":"2026-07-20T08:28:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/"},"wordCount":1406,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg","keywords":["SAP Notes"],"articleSection":["SAP Notes","SAP Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/","url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/","name":"SAP Security Notes, July 2026 - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg","datePublished":"2026-07-20T08:28:04+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"description":"All updates to SAP systems notes from july 2026, to stay current and improve the security levels of your SAP systems.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/07\/Portada-Notas-SAP.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-july-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"SAP Security Notes, July 2026"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14570","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=14570"}],"version-history":[{"count":1,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14570\/revisions"}],"predecessor-version":[{"id":14575,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14570\/revisions\/14575"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/14572"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=14570"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=14570"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=14570"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}