We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 20 and the highest CVSS score is 9.9.

 

Severity
SAP© Security advisories 20
 System Types
Affected SAP© system types

 

3747367
CVSS
9.9

Affected system type Kernel
Patchday 2026-07
Released on 2026/07/14
Description 3747367 - [CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
3753495
CVSS
9.1

Affected system type SAP Commerce Cloud
Patchday 2026-07
Released on 2026/07/14
Description 3753495 - [CVE-2026-44761] Insecure Sample Credentials in SAP Commerce Cloud
3720138
CVSS
9.1

Affected system type SAP Approuter
Patchday 2026-07
Released on 2026/07/14
Description 3720138 - [CVE-2026-27690] HTTP Request Smuggling in SAP Approuter
3727078
CVSS
9.0

Affected system type Java
Patchday 2026-07
Released on 2026/06/09
Description 3727078 - [CVE-2026-40128] Directory Traversal vulnerability in SAP NetWeaver Application Server Java (Web Container)
3758101
CVSS
8.8

Affected system type SAP Edge Integration
Patchday 2026-07
Released on 2026/07/14
Description 3758101 - [CVE-2026-40860] Multiple vulnerabilities in Apache Camel within SAP Integration Suite (Edge Integration Cell)
3692165
CVSS
8.4

Affected system type SAProuter
Patchday 2026-07
Released on 2026/07/14
Description 3692165 - [CVE-2026-0487] DLL Hijacking vulnerability in SAProuter on Microsoft Windows
3748227
CVSS
8.2

Affected system type Java
Patchday 2026-07
Released on 2026/07/14
Description 3748227 - [CVE-2026-44752] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server Java(Configuration Wizard)
3763800
CVSS
8.1

Affected system type SAP Commerce Cloud
Patchday 2026-07
Released on 2026/07/14
Description 3763800 - [Multiple CVEs] Multiple vulnerabilities in Apache Tomcat within SAP Commerce Cloud
3741519
CVSS
8.1

Affected system type SAP Approuter
Patchday 2026-07
Released on 2026/07/14
Description 3741519 - [CVE-2026-44745] Open Redirect vulnerability in SAP Approuter
3773304
CVSS
7.6

Affected system type SAP Change and...
Patchday 2026-07
Released on 2026/07/14
Description 3773304 - [CVE-2026-58233] Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)
3692004
CVSS
6.1

Affected system type SAP NetWeaver...
Patchday 2026-07
Released on 2026/04/14
Description 3692004 - [CVE-2026-34257] Open Redirect vulnerability in SAP NetWeaver Application Server ABAP
3746678
CVSS
6.1

Affected system type Java
Patchday 2026-07
Released on 2026/07/14
Description 3746678 - [CVE-2026-44759] Cross Site Scripting (XSS) vulnerability in SAP NetWeaver Enterprise Portal
3537373
CVSS
5.5

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3537373 - [CVE-2026-44769] SQL Injection vulnerability in SAP S/4HANA Project Management (PPM-PRO)
3754659
CVSS
4.7

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3754659 - [CVE-2026-44760] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (applications based on Business Server Pages)
3713902
CVSS
4.3

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3713902 - [CVE-2026-44770] Missing Authorization check in SAP S/4 HANA (Create Single Payment)
3515598
CVSS
4.3

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3515598 - [CVE-2026-44771] Missing Authorization check in SAP S/4HANA (Draft operation)
3682699
CVSS
4.2

Affected system type SAP Fiori
Patchday 2026-07
Released on 2026/06/09
Description 3682699 - [CVE-2026-24315] Path Traversal Vulnerability in SAP Fiori (launchpad)
3155685
CVSS
4.1

Affected system type ABAP
Patchday 2026-07
Released on 2026/07/14
Description 3155685 - [CVE-2026-44768] Security misconfiguration in SAP CRM (WebClient UI)
3732522
CVSS
3.7

Affected system type SAP HANA Platform
Patchday 2026-07
Released on 2026/07/14
Description 3732522 - [CVE-2026-44753] - Information Disclosure vulnerability in SAP HANA Extended Application Services classic model (User Self Service)
3726899
CVSS
3.3

Affected system type Java
Patchday 2026-07
Released on 2026/06/09
Description 3726899 - [CVE-2025-68161] Potential vulnerability in Apache Log4j library used by SAP NetWeaver AS Java