Recommendation for SAP Product Security Updates
SAP Product Security Update Advisory
Security updates addressing several vulnerabilities in SAP products have been released. Users of these products should update to the latest version.
Affected Products and Vulnerabilities
- CVE-2026-0487: SAProuter’s
KRNL64NUC 7.22, 7.22EXT,KRNL64UC 7.22, 7.22EXT, 7.53,SAP_ROUTER 7.53, 7.54,KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.17, 9.18. This vulnerability is a DLL hijacking vulnerability occurring in SAProuter. - CVE-2026-27690: Affects versions of the SAP Approuter Node.Js package prior to 20.10.0. This vulnerability is an HTTP request smuggling vulnerability.
- CVE-2026-44745: Affects versions of the SAP Approuter Node.Js package prior to 21.2.0. This vulnerability is an open redirection vulnerability.
- CVE-2026-44747: Affects SAP NetWeaver Application Server ABAP versions
KRNL64NUC 7.22, 7.22EXT,KRNL64UC 7.22, 7.22EXT, 7.53,KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20. This vulnerability is a memory corruption vulnerability. - CVE-2026-44752: Affects version
LMCTC 7.50Of SAP NetWeaver Application Server Java (Configuration Wizard). This is a XSS vulnerability. - CVE-2026-44761: Affects versions
HYCOM 2205,COMCLOUD 2211, and2211-JDK21of SAP Commerce Cloud. This vulnerability is an insecure sample credential vulnerability. - CVE-2026-58233: Affects version
CTSUPLOADCLT 1of the SAP Change and Transport System Attach Tool (ctsattach). This vulnerability is a remote code execution vulnerability.
Recommended Actions
Vulnerability Patches have been released in the latest updates. You must update to the latest patched version following the instructions on the reference website.