
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44747 is a critical memory corruption vulnerability in SAP NetWeaver Application Server (AS) ABAP that allows an authenticated attacker with low privileges to trigger out-of-bounds write conditions via logical errors in memory management, potentially leading to unauthorized data access, data modification, or system unavailability. It was published on July 14, 2026, as part of SAP's July 2026 Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, and 9.20. The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, SAP Security Notes).
The root cause is classified as CWE-787 (Out-of-bounds Write), stemming from logical errors in the memory management routines of the SAP NetWeaver AS ABAP kernel. An authenticated attacker can exploit these flaws over the network (attack vector: Network, complexity: Low, privileges required: Low, no user interaction) to write data beyond the bounds of an intended buffer, causing memory corruption. The vulnerability has a changed scope, meaning successful exploitation can impact components beyond the directly vulnerable SAP ABAP instance. No public proof-of-concept exploit code has been confirmed, but exploitation has been reported by threat intelligence sources (GitHub Advisory, SOCRadar).
Successful exploitation results in high impact across all three security dimensions: confidentiality (unauthorized data access), integrity (unauthorized data modification), and availability (system unavailability or crash). Because the CVSS scope is marked as "Changed," the impact can extend beyond the vulnerable SAP ABAP instance to other components or systems within the SAP landscape, increasing the risk of lateral movement within enterprise environments. SAP NetWeaver AS ABAP is a core enterprise platform often hosting sensitive business data, ERP processes, and financial records, making a successful attack potentially catastrophic for affected organizations (GitHub Advisory, SecurityWeek).
SM21) or developer traces; unusual ABAP runtime errors related to memory access violations./usr/sap/<SID>/work/).dw, disp+work) restarting unexpectedly or abnormal memory consumption spikes in SAP kernel processes as observed via OS-level monitoring.SAP has released patches addressing CVE-2026-44747 as part of the July 2026 Security Patch Day; organizations should apply SAP Security Note 3747367 immediately via the SAP Support Portal (SAP Security Notes). All affected kernel versions (KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20) should be updated to the patched kernel releases provided by SAP. As an interim measure, restrict network access to SAP AS ABAP instances to trusted IP ranges and enforce the principle of least privilege for all SAP user accounts to reduce the attack surface. Organizations should prioritize patching of internet-facing or externally accessible SAP systems first (SAP Patch Day, Onapsis).
The vulnerability received significant coverage across the security community following SAP's July 2026 Patch Day. Onapsis, a leading SAP security firm, highlighted it in their patch day analysis, and SecurityBridge also covered it in their July 2026 SAP security notes review (Onapsis, SecurityBridge). BleepingComputer and SecurityWeek both reported on the critical SAP NetWeaver flaws, emphasizing the 9.9 CVSS score and the risk to enterprise environments (BleepingComputer, SecurityWeek). The Hacker News specifically called out the CVSS 9.9 score in their headline, and The Hacker News weekly recap also included it, reflecting broad community awareness (The Hacker News). National CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging prompt patching.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."