CVE-2026-44747
An attacker who can log into a SAP NetWeaver Application Server ABAP can exploit a memory corruption bug that lets them read, change, or disrupt data and services. The flaw allows unauthorized access to confidential information and can cause system downtime.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
SAP NetWeaver Application Server ABAP – any version for which the bug exists, affecting organizations that run SAP ABAP applications.
Real-world impact
An attacker could read sensitive data, modify it, or make the system unavailable, potentially leading to data loss, fraud, or operational disruption.
Why this severity
The CVSS score of 9.9 reflects a network‑based attack that requires only low privilege and no user interaction, yet it compromises confidentiality, integrity, and availability, making it a critical vulnerability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 14, 2026 · 21d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 6d agoAdvisory updatedThe NVD record was last revised.