{"schema_version":1,"title":"SAP NetWeaver Application Server ABAP vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 11 vulnerabilities in SAP NetWeaver Application Server ABAP: 0 in the last 7 days and 5 in the last 90 days, 5 of them critical and 1 exploited in the wild. The most recent, CVE-2026-66779, was published on 11 August 2026.","url":"https://junglewise.ai/threats/technologies/netweaver-application-server-abap","json_url":"https://junglewise.ai/threats/technologies/netweaver-application-server-abap.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/netweaver-application-server-abap","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":0,"all_time":11,"critical":5,"exploited":1,"last_7_days":0,"last_30_days":0,"last_90_days":5,"last_365_days":10},"latest":[{"cve":"CVE-2026-66779","cvss":6.3,"epss":0.0035,"slug":"cve-2026-66779-sap-netweaver-application-server-abap-reflected-xss","title":"SAP NetWeaver Application Server ABAP reflected XSS","severity":"medium","exploited":false,"published_at":"2026-08-11T01:17:24.403+00:00","url":"https://junglewise.ai/threats/cve-2026-66779-sap-netweaver-application-server-abap-reflected-xss"},{"cve":"CVE-2026-58236","cvss":5.5,"epss":0.007,"slug":"cve-2026-58236-sap-netweaver-application-server-abap-os-command-execution-via","title":"SAP NetWeaver Application Server ABAP OS command execution via security control bypass","severity":"medium","exploited":false,"published_at":"2026-08-11T01:17:21.553+00:00","url":"https://junglewise.ai/threats/cve-2026-58236-sap-netweaver-application-server-abap-os-command-execution-via"},{"cve":"CVE-2026-34265","cvss":9.8,"epss":0.0064,"slug":"cve-2026-34265-sap-netweaver-application-server-abap-diag-protocol-memory","title":"SAP NetWeaver Application Server ABAP DIAG protocol memory corruption","severity":"critical","exploited":false,"published_at":"2026-08-11T01:17:20.24+00:00","url":"https://junglewise.ai/threats/cve-2026-34265-sap-netweaver-application-server-abap-diag-protocol-memory"},{"cve":"CVE-2026-44760","cvss":4.7,"slug":"cve-2026-44760-sap-netweaver-as-abap-cross-site-scripting-in-business-server","title":"SAP NetWeaver AS ABAP Cross-Site Scripting in Business Server Pages","severity":"medium","exploited":false,"published_at":"2026-07-14T01:16:17.91+00:00","url":"https://junglewise.ai/threats/cve-2026-44760-sap-netweaver-as-abap-cross-site-scripting-in-business-server"},{"cve":"CVE-2026-44747","cvss":9.9,"slug":"cve-2026-44747-sap-netweaver-as-abap-memory-corruption-in-memory-management","title":"SAP NetWeaver AS ABAP memory corruption in memory management","severity":"critical","exploited":false,"published_at":"2026-07-14T01:16:17.437+00:00","url":"https://junglewise.ai/threats/cve-2026-44747-sap-netweaver-as-abap-memory-corruption-in-memory-management"},{"cve":"CVE-2026-44748","cvss":9.9,"slug":"cve-2026-44748-sap-netweaver-as-abap-signature-verification-bypass-in-xml","title":"SAP NetWeaver AS ABAP signature verification bypass in XML documents","severity":"critical","exploited":false,"published_at":"2026-06-09T01:16:46.603+00:00","url":"https://junglewise.ai/threats/cve-2026-44748-sap-netweaver-as-abap-signature-verification-bypass-in-xml"},{"cve":"CVE-2026-27671","cvss":9.8,"slug":"cve-2026-27671-sap-netweaver-and-abap-platform-memory-corruption-in-sap-kernel","title":"SAP NetWeaver and ABAP Platform memory corruption in SAP Kernel","severity":"critical","exploited":false,"published_at":"2026-06-09T01:16:45.903+00:00","url":"https://junglewise.ai/threats/cve-2026-27671-sap-netweaver-and-abap-platform-memory-corruption-in-sap-kernel"},{"cve":"CVE-2026-27680","cvss":3.1,"epss":0.0003,"slug":"cve-2026-27680-sap-netweaver-as-abap-css-injection-due-to-improper-input","title":"SAP NetWeaver AS ABAP CSS injection due to improper input handling","severity":"low","exploited":false,"published_at":"2026-05-14T19:16:31.45+00:00","url":"https://junglewise.ai/threats/cve-2026-27680-sap-netweaver-as-abap-css-injection-due-to-improper-input"},{"cve":"CVE-2026-27682","cvss":4.7,"epss":0.0002,"slug":"cve-2026-27682-sap-netweaver-as-abap-reflected-xss-in-business-server-pages","title":"SAP NetWeaver AS ABAP reflected XSS in Business Server Pages","severity":"medium","exploited":false,"published_at":"2026-05-12T03:16:11.103+00:00","url":"https://junglewise.ai/threats/cve-2026-27682-sap-netweaver-as-abap-reflected-xss-in-business-server-pages"},{"cve":"CVE-2026-27688","cvss":5,"epss":0.0004,"slug":"cve-2026-27688-sap-netweaver-as-abap-missing-authorization-check-in-rfc-function","title":"SAP NetWeaver AS ABAP missing authorization check in RFC function module","severity":"medium","exploited":false,"published_at":"2026-03-10T17:38:11.497+00:00","url":"https://junglewise.ai/threats/cve-2026-27688-sap-netweaver-as-abap-missing-authorization-check-in-rfc-function"},{"cve":"CVE-2022-22536","cvss":10,"slug":"cve-2022-22536-sap-multiple-products-http-request-smuggling-vulnerability","title":"SAP Multiple Products HTTP Request Smuggling Vulnerability","severity":"critical","exploited":true,"published_at":"2022-08-18T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22536-sap-multiple-products-http-request-smuggling-vulnerability"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":1,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":1,"exploited":0,"vulnerabilities":3},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"SAP NetWeaver","slug":"netweaver","vulnerabilities":13,"url":"https://junglewise.ai/threats/technologies/netweaver"},{"name":"SAP NetWeaver Application Server Java","slug":"netweaver-as-java-servercore","vulnerabilities":11,"url":"https://junglewise.ai/threats/technologies/netweaver-as-java-servercore"},{"name":"SAP Businessobjects-Bi-Platform","slug":"businessobjects-business-intelligence-platform","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/businessobjects-business-intelligence-platform"},{"name":"SAP Manufacturing Integration and Intelligence","slug":"manufacturing-integration-and-intelligence","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/manufacturing-integration-and-intelligence"},{"name":"SAP NetWeaver Application Server for ABAP","slug":"netweaver-application-server-for-abap","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/netweaver-application-server-for-abap"},{"name":"SAP S/4HANA","slug":"s-4hana","vulnerabilities":5,"url":"https://junglewise.ai/threats/technologies/s-4hana"},{"name":"SAP Commerce Cloud","slug":"commerce-cloud","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/commerce-cloud"},{"name":"SAP S/4HANA Finance","slug":"s-4hana-finance","vulnerabilities":3,"url":"https://junglewise.ai/threats/technologies/s-4hana-finance"}],"technology":{"hub":true,"name":"SAP NetWeaver Application Server ABAP","slug":"netweaver-application-server-abap","vendor":{"name":"SAP","slug":"sap","url":"https://junglewise.ai/threats/vendors/sap"},"aliases":[],"category":"web-server","homepage":"https://www.sap.com/products/technology-platform/netweaver.html","description":"An application server for SAP applications written in the ABAP programming language.","url":"https://junglewise.ai/threats/technologies/netweaver-application-server-abap"},"most_severe":[{"cve":"CVE-2022-22536","cvss":10,"slug":"cve-2022-22536-sap-multiple-products-http-request-smuggling-vulnerability","title":"SAP Multiple Products HTTP Request Smuggling Vulnerability","severity":"critical","exploited":true,"published_at":"2022-08-18T00:00:00+00:00","url":"https://junglewise.ai/threats/cve-2022-22536-sap-multiple-products-http-request-smuggling-vulnerability"},{"cve":"CVE-2026-44747","cvss":9.9,"slug":"cve-2026-44747-sap-netweaver-as-abap-memory-corruption-in-memory-management","title":"SAP NetWeaver AS ABAP memory corruption in memory management","severity":"critical","exploited":false,"published_at":"2026-07-14T01:16:17.437+00:00","url":"https://junglewise.ai/threats/cve-2026-44747-sap-netweaver-as-abap-memory-corruption-in-memory-management"},{"cve":"CVE-2026-44748","cvss":9.9,"slug":"cve-2026-44748-sap-netweaver-as-abap-signature-verification-bypass-in-xml","title":"SAP NetWeaver AS ABAP signature verification bypass in XML documents","severity":"critical","exploited":false,"published_at":"2026-06-09T01:16:46.603+00:00","url":"https://junglewise.ai/threats/cve-2026-44748-sap-netweaver-as-abap-signature-verification-bypass-in-xml"},{"cve":"CVE-2026-34265","cvss":9.8,"epss":0.0064,"slug":"cve-2026-34265-sap-netweaver-application-server-abap-diag-protocol-memory","title":"SAP NetWeaver Application Server ABAP DIAG protocol memory corruption","severity":"critical","exploited":false,"published_at":"2026-08-11T01:17:20.24+00:00","url":"https://junglewise.ai/threats/cve-2026-34265-sap-netweaver-application-server-abap-diag-protocol-memory"},{"cve":"CVE-2026-27671","cvss":9.8,"slug":"cve-2026-27671-sap-netweaver-and-abap-platform-memory-corruption-in-sap-kernel","title":"SAP NetWeaver and ABAP Platform memory corruption in SAP Kernel","severity":"critical","exploited":false,"published_at":"2026-06-09T01:16:45.903+00:00","url":"https://junglewise.ai/threats/cve-2026-27671-sap-netweaver-and-abap-platform-memory-corruption-in-sap-kernel"},{"cve":"CVE-2026-66779","cvss":6.3,"epss":0.0035,"slug":"cve-2026-66779-sap-netweaver-application-server-abap-reflected-xss","title":"SAP NetWeaver Application Server ABAP reflected XSS","severity":"medium","exploited":false,"published_at":"2026-08-11T01:17:24.403+00:00","url":"https://junglewise.ai/threats/cve-2026-66779-sap-netweaver-application-server-abap-reflected-xss"},{"cve":"CVE-2026-58236","cvss":5.5,"epss":0.007,"slug":"cve-2026-58236-sap-netweaver-application-server-abap-os-command-execution-via","title":"SAP NetWeaver Application Server ABAP OS command execution via security control bypass","severity":"medium","exploited":false,"published_at":"2026-08-11T01:17:21.553+00:00","url":"https://junglewise.ai/threats/cve-2026-58236-sap-netweaver-application-server-abap-os-command-execution-via"},{"cve":"CVE-2026-27688","cvss":5,"epss":0.0004,"slug":"cve-2026-27688-sap-netweaver-as-abap-missing-authorization-check-in-rfc-function","title":"SAP NetWeaver AS ABAP missing authorization check in RFC function module","severity":"medium","exploited":false,"published_at":"2026-03-10T17:38:11.497+00:00","url":"https://junglewise.ai/threats/cve-2026-27688-sap-netweaver-as-abap-missing-authorization-check-in-rfc-function"},{"cve":"CVE-2026-27682","cvss":4.7,"epss":0.0002,"slug":"cve-2026-27682-sap-netweaver-as-abap-reflected-xss-in-business-server-pages","title":"SAP NetWeaver AS ABAP reflected XSS in Business Server Pages","severity":"medium","exploited":false,"published_at":"2026-05-12T03:16:11.103+00:00","url":"https://junglewise.ai/threats/cve-2026-27682-sap-netweaver-as-abap-reflected-xss-in-business-server-pages"},{"cve":"CVE-2026-44760","cvss":4.7,"slug":"cve-2026-44760-sap-netweaver-as-abap-cross-site-scripting-in-business-server","title":"SAP NetWeaver AS ABAP Cross-Site Scripting in Business Server Pages","severity":"medium","exploited":false,"published_at":"2026-07-14T01:16:17.91+00:00","url":"https://junglewise.ai/threats/cve-2026-44760-sap-netweaver-as-abap-cross-site-scripting-in-business-server"}],"generated_at":"2026-09-26T09:11:00.170868+00:00"}