Junglewise Threat Intelligence

CVE-2026-44747: SAP NetWeaver AS ABAP memory corruption in memory management

CVE-2026-44747 · Severity: critical · CVSS 9.9 · Published 2026-07-14

Technologies: SAP NetWeaver Application Server ABAP. Vendors: SAP.

Executive brief

SAP NetWeaver Application Server ABAP, a core platform for running business applications, is affected by a critical memory management vulnerability. An authenticated user can exploit this flaw to corrupt system memory, potentially leading to the theft of sensitive data, unauthorized modification of records, or a complete system shutdown. This poses a significant risk to business operations and data integrity across the SAP environment.

Technical details

A critical out-of-bounds write vulnerability (CWE-787) exists in SAP NetWeaver Application Server ABAP due to logical errors in memory management. An authenticated attacker can exploit this over the network with low complexity to trigger memory corruption. Successful exploitation allows for a scope-crossing attack that impacts the confidentiality, integrity, and availability of the entire application. The vulnerability affects multiple kernel versions including 7.22, 7.53, 7.54, and various 9.x releases. SAP has released security note 3747367 to address this issue.

Affected products

  • SAP NetWeaver Application Server ABAP KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, KERNEL 7.22, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19, 9.20

Timeline

  • 2026-07-14: advisory: Initial publication by SAP and NVD
  • 2026-07-14: patched: SAP released security note 3747367

References

Related threats