Enterprise software maker SAP on Tuesday announced the release of 20 new and updated security notes as part of its July 2026 security patch day.
The most severe of the resolved vulnerabilities is CVE-2026-44747 (CVSS score of 9.9), a memory corruption bug in NetWeaver Application Server ABAP.
Successful exploitation of the security defect could allow an attacker to access and modify data, and cause system unavailability, SAP security firm Onapsis explains.
SAP customers are strongly advised to apply the fresh patches to resolve the flaw, but can also “disable all ICF nodes with a specific property in transaction SICF” as a temporary workaround.
The second security note released on SAP’s July 2026 security patch day fixes a critical HTTP request smuggling issue in Approuter, tracked as CVE-2026-27690 (CVSS score of 9.1).










