CVE-2026-44747
SAP NetWeaver Application Server ABAP vulnerability analysis and mitigation

Overview

CVE-2026-44747 is a critical memory corruption vulnerability in SAP NetWeaver Application Server (AS) ABAP that allows an authenticated attacker with low privileges to trigger out-of-bounds write conditions via logical errors in memory management, potentially leading to unauthorized data access, data modification, or system unavailability. It was published on July 14, 2026, as part of SAP's July 2026 Security Patch Day. Affected kernel versions include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, and 9.20. The vulnerability carries a CVSS v3.1 base score of 9.9 (Critical) (GitHub Advisory, SAP Security Notes).

Technical details

The root cause is classified as CWE-787 (Out-of-bounds Write), stemming from logical errors in the memory management routines of the SAP NetWeaver AS ABAP kernel. An authenticated attacker can exploit these flaws over the network (attack vector: Network, complexity: Low, privileges required: Low, no user interaction) to write data beyond the bounds of an intended buffer, causing memory corruption. The vulnerability has a changed scope, meaning successful exploitation can impact components beyond the directly vulnerable SAP ABAP instance. No public proof-of-concept exploit code has been confirmed, but exploitation has been reported by threat intelligence sources (GitHub Advisory, SOCRadar).

Impact

Successful exploitation results in high impact across all three security dimensions: confidentiality (unauthorized data access), integrity (unauthorized data modification), and availability (system unavailability or crash). Because the CVSS scope is marked as "Changed," the impact can extend beyond the vulnerable SAP ABAP instance to other components or systems within the SAP landscape, increasing the risk of lateral movement within enterprise environments. SAP NetWeaver AS ABAP is a core enterprise platform often hosting sensitive business data, ERP processes, and financial records, making a successful attack potentially catastrophic for affected organizations (GitHub Advisory, SecurityWeek).

Exploitation steps

  1. Reconnaissance: Identify SAP NetWeaver AS ABAP instances running affected kernel versions (KRNL64NUC/KRNL64UC 7.22, KERNEL 7.22/7.53/7.54/7.77/7.89/7.93, or 9.16–9.20) using network scanning tools or SAP-specific discovery techniques.
  2. Obtain authenticated access: Acquire low-privileged credentials to the target SAP system — this could be via phishing, credential stuffing, or use of default/weak SAP accounts.
  3. Trigger memory management flaw: Send crafted requests or ABAP function module calls that exploit the logical errors in the kernel's memory management routines, causing an out-of-bounds write condition.
  4. Achieve memory corruption: The malformed input causes the kernel to write data beyond the intended buffer boundary, corrupting adjacent memory structures.
  5. Leverage impact: Depending on what memory is corrupted, the attacker may achieve unauthorized read access to sensitive data, modify business-critical data, or crash the SAP application server, causing denial of service (GitHub Advisory, SOCRadar).

Indicators of compromise

  • Logs: Unexpected SAP kernel crash dumps (short dumps) or work process terminations in the SAP system log (SM21) or developer traces; unusual ABAP runtime errors related to memory access violations.
  • Logs: Repeated or anomalous authenticated requests from low-privileged accounts to kernel-level function modules or RFC-enabled function groups.
  • Network: Unusual outbound connections from the SAP application server host following authenticated sessions from unexpected source IPs.
  • File System: Unexpected core dump files or memory dump artifacts in the SAP kernel work directory (e.g., /usr/sap/<SID>/work/).
  • Process: SAP work processes (dw, disp+work) restarting unexpectedly or abnormal memory consumption spikes in SAP kernel processes as observed via OS-level monitoring.

Mitigation and workarounds

SAP has released patches addressing CVE-2026-44747 as part of the July 2026 Security Patch Day; organizations should apply SAP Security Note 3747367 immediately via the SAP Support Portal (SAP Security Notes). All affected kernel versions (KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20) should be updated to the patched kernel releases provided by SAP. As an interim measure, restrict network access to SAP AS ABAP instances to trusted IP ranges and enforce the principle of least privilege for all SAP user accounts to reduce the attack surface. Organizations should prioritize patching of internet-facing or externally accessible SAP systems first (SAP Patch Day, Onapsis).

Community reactions

The vulnerability received significant coverage across the security community following SAP's July 2026 Patch Day. Onapsis, a leading SAP security firm, highlighted it in their patch day analysis, and SecurityBridge also covered it in their July 2026 SAP security notes review (Onapsis, SecurityBridge). BleepingComputer and SecurityWeek both reported on the critical SAP NetWeaver flaws, emphasizing the 9.9 CVSS score and the risk to enterprise environments (BleepingComputer, SecurityWeek). The Hacker News specifically called out the CVSS 9.9 score in their headline, and The Hacker News weekly recap also included it, reflecting broad community awareness (The Hacker News). National CERTs including Ireland's NCSC and Singapore's CSA issued advisories urging prompt patching.

Additional resources


SourceThis report was generated using AI

Related SAP NetWeaver Application Server ABAP vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-44747CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJul 14, 2026
CVE-2026-44748CRITICAL9.9
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27671CRITICAL9.8
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-44751HIGH7.1
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoYesJun 09, 2026
CVE-2026-27680MEDIUM4.3
  • SAP NetWeaver Application Server ABAP logoSAP NetWeaver Application Server ABAP
  • cpe:2.3:a:sap:netweaver_application_server_abap
NoNoMay 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management