The images in this article were generated with artificial intelligence. How we publish
SAP has published the June 2026 patch package that fixes 15 vulnerabilities, including four identified as critical that affect central platforms such as SAP NetWeaver and SAP Commerce Cloud. These failures are not merely theoretical: they touch components that measure identity, data processing and electronic commerce, so their exploitation can result in unauthorized access, exfiltration of information or interruption of critical business services.
Two of the most serious vulnerabilities deserve immediate attention: CVE-2026-44748, a case of XML Signature Wrapping that may allow to omit authentication in SAML environments, and CVE-2026-27671, an exploitable memory corruption by RFC requests without authentication. The first de facto emptiness of the SAML assertions if an attacker with normal access manages to manipulate signed messages; the second allows unexpected performance on the server that, in a real scenario, could lead to climbing or remote execution. SAP publishes the note with the patches and guidance in its safety bulletin, so the organizations concerned should consult it as soon as possible: SAP Security Bulletin - June 2026.

Conceptually, XML signature vulnerabilities (XML Signature Wrapping) exploit the way systems locate and validate the signed part of a signed XML document: if the verifier takes the signature of a node but processes other data, an attacker can insert legitimate and false assertions into the same structure. To better understand this kind of attack and its mitigation at the design level, the security community offers useful resources to review: OWASP - XML Signature Wrapping.
In addition to critical failures, the package fixes high and medium severity problems related to Apache Tomcat, incomplete clearance checks, SQL injections, route traversal, XSS and mail supplanting. Although some technical details and complete mitigation are available only within the SAP client portal, the existence of multiple vectors suggests that it is not enough to apply isolated patches: a coordinated strategy of mediation and detection is required.
As for priorities, immediately prioritize the application of patches for CVE-2026-44748 and CVE-2026-27671, test the corrections in pre-production environments and program maintenance windows to apply the production fixes. If you cannot park immediately, implement compensatory controls: limit network access to RFC and administrative ports and endpoints, tighten SAML confidence relationships (review certificates and validation of URis), deploy WAF rules that block suspicious XML loads and apply microsegmentation to isolate critical systems.
Do not underestimate detection: configure rules in your SIEM and EDR to look for relevant indicators, such as attempts to request RFC with abnormal load, SAML messages with duplicated structure or valid but inconsistent signatures, memory exceptions and rebeginnings of the Application Server. Audit authentication and SSO log, and look for off-time access signals to management consoles or side movements to ERP systems and product catalogues.

For operations and security equipment, the practical response should include comprehensive inventory of NetWeaver and Commerce Cloud facilities, verification of ABAP and Java Application Server versions, coordination with maintenance changes and regression tests. Keep clear backup and rollback procedures before deploying patches and inform business units of the expected impact and mitigation deadlines to avoid operational surprises.
If your organization depends on SAP Commerce Cloud for online sales, also consider specific reviews of the security of the purchase chain and customer authentication, because vulnerabilities to web components and Tomcat can facilitate fraud or order handling. Be aware of additional and related CVE notices to avoid overtaking chained patches; you can consult specific CVE entries for more technical context: CVE-2026-44748 and CVE-2026-27671.
Finally, incorporate the lesson into your vulnerability management program: maintain a priority based on exposure and asset criticality, automate internal and external scans, and exercise post-patch penetration and validation tests to confirm that controls work. Technical patches and controls are urgent, but real risk reduction also requires processes, continuous monitoring and coordination between security, operations and business.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Google reports DNS kidnapping: TLS certificates for google.com.gh, google.sl and google.as
Google reported on October 6 that attackers managed to issue unauthorized HTTPS certificates for Google and YouTube names after compromising authoritative DNS records of three t...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...