CuraSec

Plan archived

SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw

2026-07-15 12:11 UTC · The Hacker News · read the source ↗ #sap#critical-vulnerability#enterprise-erp
  • Engineer — Plan: SAP NetWeaver ABAP is widely deployed in enterprise environments and this authenticated out-of-bounds write carries a 9.9 CVSS; no KEV listing, EPSS near zero, and no public PoC mean there’s no immediate exploitation pressure, but apply SAP’s July 2026 security patches in your next maintenance window.
  • SOC/IR — Skip
  • Leader — Skip
  • Signals: CVE-2026-44747 — CISA KEV: not listed, EPSS 0.00, no public PoC found
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.