- Description
- SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to obtain a valid signed message and send modified signed XML documents to the verifier. This may result in acceptance of tampered identity information leading to unauthorized access to sensitive user data and potential disruption of normal system usage. This causes a high impact on confidentiality, integrity and availability of the application.
- Source
- cna@sap.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- cna@sap.com
- CWE-347
- Hype score
- Not currently trending
ثغرة حرجة في خوادم ساب تتيح للمهاجم تزوير الهوية وتجاوز المصادقة بالكامل المعرّف : CVE-2026-44748 درجة الخطورة : 9.9 (CVSS) - Critical الإصدارات المتأثرة : SAP NetWeaver AS ABAP / A
@KasperskyDev
15 Jun 2026
59 Impressions
1 Retweet
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SAP June Patch Day: 15 security notes, 4 critical. CVE-2026-44748 (CVSS 9.9) — XML Signature Wrapping bypass in NetWeaver SAML. CVE-2026-27671 (CVSS 9.8) — unauthenticated memory corruption in ABAP RFC gateway. https://t.co/URyHYrF8Aa #CyberSecurity #Vulne https://t.co/vngyJi
@securitydailyr
11 Jun 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Could Allow Full Authentication Bypass https://t.co/19RvwBdR5H SAP Security Patch Day June 2026: Critical CVE-2026-44748 SAML Flaw Could Allow Full Authentication Bypass On June 9, 2026, SAP released its mont
@f1tym1
10 Jun 2026
30 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NEW: SAP June Patch Day — 4 critical flaws, top CVSS 9.9. The worst: CVE-2026-44748 lets a low-privileged user forge SAML assertions and bypass authentication entirely on NetWeaver ABAP. CVE-2026-27671 (CVSS 9.8) is unauthenticated memory corruption via crafted RFC request
@CyberAlertsHQ
9 Jun 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
SAP released 15 security notes addressing four critical flaws including CVE-2026-44748 and CVE-2026-27671 in NetWeaver and other core products, Belgium's Centre for Cybersecurity said. https://t.co/V0QlgiVYvz
@threatcluster
9 Jun 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: #SAP has released security updates for 15 vulnerabilities in several of their products, including 4 critical vulnerabilities: #CVE-2026-44748; #CVE-2026-27671; #CVE-2026-40128 and #CVE-2026-22732. Read our advisory here: https://t.co/cVlLvwsEYZ #Patch #Patch #Patch
@CCBalert
9 Jun 2026
107 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨Critical - Two SAP NetWeaver Flaws Patched in June 2026 (CVE-2026-44748, CVE-2026-40128) SAP's June 2026 Security Patch Day fixes two critical SAP NetWeaver vulnerabilities, both with a scope change and full C/I/A impact. CVE-2026-44748 (9.9) - AS ABAP and ABAP Platform: an
@UpwindMDR
9 Jun 2026
128 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-44748 — CVSS 9.9/10 ██████████ SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated attacker with normal privileges to... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/QkbkF2xXiX
@OrizonCyber
9 Jun 2026
88 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes