SAP’s July 2026 Security Patch Day, released July 14, shipped 16 new security notes plus one GitHub security advisory and updates to three previously released notes, with two rated critical. CVE-2026-44747, scored 9.9, is a memory corruption vulnerability in the SAP NetWeaver Application Server ABAP kernel, spanning versions 7.22 through 9.20. CVE-2026-44761, scored 9.1, covers insecure sample credentials shipped in SAP Commerce Cloud releases HY_COM 2205 and COM_CLOUD 2211. Two further high-severity notes address an HTTP request smuggling flaw (CVE-2026-27690, 9.1) and a directory traversal issue (CVE-2026-40128, 9.0). SAP is urging customers to apply the patches through the support portal on priority.

The pairing of these two flaws matters more than either score alone. NetWeaver and Commerce Cloud sit underneath core enterprise resource planning and e-commerce operations, systems that were once tucked behind internal networks but are now routinely internet-facing to support partner and customer access. A memory corruption bug in the application server kernel and hardcoded sample credentials on a customer-facing commerce platform are both remote entry points into systems holding financial and customer data, not isolated internal risks.

The insecure-credentials bug is the more consequential of the two in practice, even at a full point lower on the CVSS scale. Exploiting a memory corruption flaw generally still requires an attacker to build or acquire working exploit code. Sample credentials left active in a shipped configuration need none of that; once the advisory names the affected versions, the flaw is directly usable by anyone scanning for it. This publication has already tracked how fast that scanning-to-exploitation window has compressed for edge platforms, reporting on NetScaler and ColdFusion flaws weaponized within hours of disclosure. SAP’s ERP and commerce layer is now operating on the same compressed timeline, which means patch prioritization for these two notes should not wait for the next scheduled maintenance window.

Source: SAP Security Patch Day, July 2026