Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-44747
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-44747 is a critical memory corruption vulnerability in SAP NetWeaver Application Server (AS) ABAP that allows an authenticated attacker with low privileges to trigger unauthorized data access, modification, or system unavailability via logical errors in memory management. It was published on July 14, 2026, as part of SAP's July 2026 Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, and 9.20. The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) with a changed scope, reflecting its potential to impact resources beyond the vulnerable component (GitHub Advisory, SAP Security Notes).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write), stemming from logical errors in the memory management routines of the SAP NetWeaver AS ABAP kernel. An authenticated attacker with low privileges can exploit these flaws over the network without user interaction, causing the application to write data outside the bounds of an intended buffer, resulting in memory corruption. The changed scope in the CVSS vector indicates that a successful exploit can affect resources beyond the directly vulnerable component, potentially impacting other system processes or data stores. The vulnerability is referenced in SAP Security Note 3747367 and was detected by Qualys scanner (detection ID 531834) (GitHub Advisory, SAP Security Notes).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability of the affected SAP NetWeaver AS ABAP instance. An attacker can gain unauthorized access to sensitive business data, modify critical application data, or render the system unavailable — all of which are severe outcomes for enterprise environments that rely on SAP for core business operations. The changed scope means the impact can extend beyond the directly vulnerable component, increasing the risk of lateral movement or cascading failures across interconnected SAP systems (GitHub Advisory, SOCRadar).

Exploitability

No public proof-of-concept exploit code has been confirmed, though exploitation has been reported by threat intelligence sources including SOCRadar (SOCRadar). The EPSS score is approximately 0.44–0.53%, placing it in the 42nd percentile for exploitation probability within 30 days. NVD's SSVC assessment notes exploitation as "none" confirmed at time of publication, and the vulnerability is not currently listed in the CISA KEV catalog. The attack does not require automation (not automatable per SSVC), but the low privilege requirement and network-accessible attack vector make it an attractive target for authenticated insiders or compromised accounts (GitHub Advisory).

Mitigation and workarounds

SAP has released patches addressing CVE-2026-44747 as part of the July 2026 Security Patch Day; organizations should apply SAP Security Note 3747367 immediately via the SAP Support Portal. Administrators should prioritize patching SAP NetWeaver AS ABAP instances running affected kernel versions (KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22/7.53/7.54/7.77/7.89/7.93, and 9.x series up to 9.20). As an interim measure, restrict network access to SAP NetWeaver AS ABAP interfaces to trusted users and networks, and enforce the principle of least privilege for all SAP user accounts. Monitor SAP systems for anomalous behavior while patching is in progress (SAP Security Notes, GitHub Advisory).

Community reactions

The vulnerability received broad coverage across the security community following SAP's July 2026 Patch Day. Outlets including BleepingComputer, The Hacker News, SecurityWeek, and Heise reported on the critical CVSS 9.9 score and the risk to enterprise SAP environments (BleepingComputer, The Hacker News, SecurityWeek). SAP security specialists Onapsis, SecurityBridge, RedRays, and Layer Seven Security published dedicated patch day analyses highlighting this CVE as the most critical issue of the release (Onapsis, SecurityBridge). Government cybersecurity agencies including Ireland's NCSC and Singapore's CSA issued alerts urging immediate patching (NCSC Ireland, CSA Singapore).

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44756CRITICAL10
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-58240CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-66767HIGH7.7
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesSep 08, 2026
CVE-2026-66779MEDIUM6.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoAug 11, 2026
CVE-2026-58236MEDIUM5.5
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesAug 11, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management