# SAP Patches Batch of July 2026 Flaws

Published: 2026-07-15 · Severity: medium
Canonical: https://vorant.io/reports/0df9f415-e649-56db-a52e-e4e76dd71694/sap-patches-batch-of-july-2026-flaws

> CERT-FR flags a French advisory covering SAP's July 2026 patch day, fixing 22 CVEs across NetWeaver, S/4HANA, Fiori, Commerce Cloud and other products, some enabling RCE and SQL injection.

CERT-FR published an advisory summarizing SAP's July 2026 Security Patch Day, which addresses multiple vulnerabilities across a wide range of SAP products. Affected components include NetWeaver Application Server (ABAP and Java variants), S/4HANA (including Create Single Payment, Draft operation, and Project Management/PPM-PRO modules), Fiori Launchpad, Commerce Cloud, CRM WebClient UI, HANA Extended Application Services, Integration Suite (Edge Integration Cell), SAProuter on Windows, and the Change and Transport System Attach Tool. Impact categories span remote code execution, data confidentiality breaches, security policy bypass, SQL injection, and cross-site scripting (XSS).

The advisory does not indicate evidence of active exploitation; it is a routine notification directing administrators to SAP's official security bulletin for patch details across 22 distinct CVEs. Given the breadth of enterprise-critical SAP deployments affected — spanning ERP, CRM, integration, and portal technologies — organizations running unpatched versions of these components should prioritize applying the vendor's July 2026 fixes to mitigate risks of remote code execution and data exposure.

No specific threat actor, malware, or campaign is referenced in this advisory; it functions purely as a vulnerability disclosure and patch notification for SAP customers.

## Mentioned in this report

- Vulnerabilities: CVE-2025-68161, CVE-2026-0487, CVE-2026-24315, CVE-2026-27690, CVE-2026-33454, CVE-2026-40128, CVE-2026-40453, CVE-2026-40860, CVE-2026-41293, CVE-2026-43512, CVE-2026-43515, CVE-2026-44745, CVE-2026-44747, CVE-2026-44752, CVE-2026-44753, CVE-2026-44759, CVE-2026-44760, CVE-2026-44761, CVE-2026-44767, CVE-2026-44768, CVE-2026-44769, CVE-2026-44770, CVE-2026-44771, CVE-2026-58233

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0877

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0df9f415-e649-56db-a52e-e4e76dd71694/sap-patches-batch-of-july-2026-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
