VORANT. Threat Intelligence Sign in Get the full feed

SAP Patches Batch of July 2026 Flaws

medium vulnerability

CERT-FR flags a French advisory covering SAP's July 2026 patch day, fixing 22 CVEs across NetWeaver, S/4HANA, Fiori, Commerce Cloud and other products, some enabling RCE and SQL injection.

CERT-FR published an advisory summarizing SAP's July 2026 Security Patch Day, which addresses multiple vulnerabilities across a wide range of SAP products. Affected components include NetWeaver Application Server (ABAP and Java variants), S/4HANA (including Create Single Payment, Draft operation, and Project Management/PPM-PRO modules), Fiori Launchpad, Commerce Cloud, CRM WebClient UI, HANA Extended Application Services, Integration Suite (Edge Integration Cell), SAProuter on Windows, and the Change and Transport System Attach Tool. Impact categories span remote code execution, data confidentiality breaches, security policy bypass, SQL injection, and cross-site scripting (XSS).

The advisory does not indicate evidence of active exploitation; it is a routine notification directing administrators to SAP's official security bulletin for patch details across 22 distinct CVEs. Given the breadth of enterprise-critical SAP deployments affected — spanning ERP, CRM, integration, and portal technologies — organizations running unpatched versions of these components should prioritize applying the vendor's July 2026 fixes to mitigate risks of remote code execution and data exposure.

No specific threat actor, malware, or campaign is referenced in this advisory; it functions purely as a vulnerability disclosure and patch notification for SAP customers.

Mentioned in this report

Vulnerabilities CVE-2025-68161CVE-2026-0487CVE-2026-24315CVE-2026-27690CVE-2026-33454CVE-2026-40128CVE-2026-40453CVE-2026-40860CVE-2026-41293CVE-2026-43512CVE-2026-43515CVE-2026-44745CVE-2026-44747CVE-2026-44752CVE-2026-44753CVE-2026-44759CVE-2026-44760CVE-2026-44761CVE-2026-44767CVE-2026-44768CVE-2026-44769CVE-2026-44770CVE-2026-44771CVE-2026-58233

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0877

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free