-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Security Patch Day - June 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.
On 9th of June 2026, SAP security patch day saw the release of 15 new security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2026-44748] XML Signature Wrapping in SAML Authentication in SAP NetWeaver AS ABAP and ABAP Platform Product - SAP NetWeaver AS ABAP and ABAP Platform | Critical | ||
[CVE-2026-27671] Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform Product - SAP NetWeaver AS ABAP and ABAP Platform | Critical | ||
[CVE-2026-22732] Potential Spring Security vulnerability within SAP Commerce Cloud and SAP Data Hub Product - SAP Commerce Cloud and SAP Data Hub | Critical | ||
[CVE-2026-40128] Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container) Product - SAP NetWeaver Application Server Java (Web Container) | Critical | ||
[CVE-2026-29145] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud | High | ||
[CVE-2026-44751] Missing Authorization check in Application Server ABAP of SAP NetWeaver and ABAP Platform Product - SAP NetWeaver AS ABAP and ABAP Platform | High | ||
[CVE-2026-44754] Missing caller identification check-in for ODP Data Replication APIs Product - ODP Data Replication APIs | Medium | ||
[CVE-2026-44744] SQL Injection vulnerability in SAP S/4HANA Product - SAP S/4HANA | Medium | ||
[CVE-2026-44746] Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver AS Java (JDBC Test Servlet) | Medium | ||
[CVE-2026-44757] Cross-Site Scripting (XSS) vulnerability in SAP Wily Introscope Enterprise Manager | Medium | ||
[CVE-2026-44750] Missing Authorization check in SAP MDG (Review Match Groups Application) Product - SAP MDG (Review Match Groups Application) | Medium | ||
[CVE-2026-44755] Email Spoofing vulnerability in SAP Business Objects Business Intelligence Platform Product - SAP Business Objects Business Intelligence Platform | Medium | ||
[CVE-2026-24315] Path Traversal Vulnerability in SAP Fiori (launchpad) | Medium | ||
[CVE-2026-44743] Security Misconfiguration vulnerability in SAP Business Objects | Low | ||
[CVE-2025-68161] Potential vulnerability in Apache Log4j library used by SAP NetWeaver AS Java Product - SAP NetWeaver AS Java | Low |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.