Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-23 · updated: 2026-09-23 · tags: [cve] · confidence: high · severity: critical · affected_sectors: [technology, finance, government] · au_impact: false

CVE-2026-44747

Summary

A critical out-of-bounds write in SAP NetWeaver Application Server ABAP, scored CVSS 9.9, that could let an authenticated attacker corrupt memory and reach unauthorised data access, modification or unavailability.

Details

The authenticated precondition matters for triage: this is not a perimeter flaw, so it ranks behind an unauthorised-RCE on the same estate — but an authenticated attacker in an SAP landscape is a realistic starting point given how often service accounts and integration users are shared or over-privileged. The digest recorded it as the headline item of SAP's July 2026 updates, released alongside the Approuter smuggling flaw CVE-2026-27690; memory corruption in the ABAP application server affects the platform under every business module, so the patch is a platform-level obligation rather than a module one.

Attribute Detail
CVE CVE-2026-44747
CVSS 9.9
Vendor / product SAP (NetWeaver AS ABAP)
Reported in the digest 2026-07-15

Related Pages

Sources: raw/digests/Cyber-Digest-2026-07-15.md