CVE-2026-44747

Published Jul 14, 2026

Last updated 8 days ago

Overview

Description
SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unauthorized data access, modification, or system unavailability. This has high impact on confidentiality, integrity, and availability of the application.
Source
cna@sap.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.9
Impact score
6
Exploitability score
3.1
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-787

Social media

Hype score
Not currently trending
  1. ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-44761 ❗ CVE-2026-44747 ❗ CVE-2026-27690 ➡️ Más info: https://t.co/VxDSRqAJ34 https://t.co/6Fnqu3t1hg

    @CERTpy

    22 Jul 2026

    197 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. SAP、2026年7月のセキュリティパッチデーでCVSS 9.9のNetWeaver重大脆弱性を含む16件を修正(CVE-2026-44747, CVE-2026-27690) https://t.co/TICPuVyMS9 #セキュリティ対策Lab #security #securitynews

    @securityLab_jp

    16 Jul 2026

    120 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. SAP patches 16 vulnerabilities in its July 2026 security update, three critical. NetWeaver AS ABAP gets fixed for a memory corruption bug (CVE-2026-44747) that risks unauthorized data access or system outages. SAP Commerce Cloud shipped with default credentials (CVE-2026-44761),

    @XavierRiveraX

    14 Jul 2026

    83 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 SAP's July 2026 Patch Day fixes 16 new security issues, led by a critical memory corruption flaw in NetWeaver AS ABAP (CVE-2026-44747, CVSS 9.9) affecting kernel versions 7.22 through 9.20 — both legacy and current deployments. ⚠️ A second critical bug (CVE-2026-27690

    @techepages

    14 Jul 2026

    45 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2026-44747 — CVSS 9.9/10 ██████████ SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/dmigu9DfUM

    @OrizonCyber

    14 Jul 2026

    71 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

References

Sources include official advisories and independent security research.