CVE-2026-27690 – SAP NetWeaver Application Server ABAP, SAP Approuter, SAP Commerce Cloud

CVSS 9.1 CRITICAL Critical - Same Day Deployment

“Critical vulnerabilities demand immediate action because a single unpatched system can become the weakest link across the enterprise.”

SAP has released security updates addressing three critical vulnerabilities affecting SAP NetWeaver Application Server ABAP, SAP Approuter, and SAP Commerce Cloud. These issues could allow attackers to compromise sensitive data, modify application content, or disrupt business operations if left unpatched. CVE-2026-44747 has a CVSS score of 9.9, which is Critical severity. CVE-2026-27690 has a CVSS score of 9.1, which is Critical severity. CVE-2026-44761 has a CVSS score of 9.1, which is Critical severity.

The update addresses a memory corruption issue in SAP NetWeaver Application Server ABAP that could enable unauthorized data access, modification, or system unavailability. It also resolves an HTTP Request Smuggling vulnerability in SAP Approuter that may expose user responses and impact service availability. In addition, the update removes the risk posed by publicly documented sample OAuth2 credentials in SAP Commerce Cloud that could otherwise allow unauthorized access to APIs and sensitive data. No verified real-world exploitation or public proof-of-concept has been confirmed for these vulnerabilities.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-444
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.