CRITICAL 6 min read 16 Jul 2026

SAP releases a patch for critical CVE-2026-44747 in NetWeaver Application Server ABAP

What changed Finding 01 records a patch release for critical CVE-2026-44747. The vulnerability is an out-of-bounds write in SAP NetWeaver Application Server ABAP that an authenticated attacker could use to corrupt memory, potentially leading to unauthorised data access, modification or system unavailability.

Key findings
01
SAP patches critical NetWeaver ABAP memory flaw CVE-2026-44747
CRITICAL
SAP has released an update addressing CVE-2026-44747, a CVSS 9.9 out-of-bounds write in SAP NetWeaver Application Server ABAP. An authenticated attacker could exploit logical errors in memory management to corrupt memory, potentially causing unauthorised data access, data modification or system unavailability.
02
CVE-2025-11698 can place affected controllers into a non-recoverable fault
CRITICAL
CVE-2025-11698 is reported in 5380, 5480 and 5580 controllers using boot firmware below version 1.072. A malicious user could potentially write invalid file data to a controller, causing it to enter a major non-recoverable fault and creating a denial-of-service condition.
03
Eight CVEs include PCX decoding and memory-safety weaknesses
HIGH
This advisory retains CVE-2020-35653, CVE-2020-35655, CVE-2021-25287, CVE-2021-25288, CVE-2021-25290, CVE-2021-25292, CVE-2021-25293 and CVE-2021-27921.
04
CVE-2026-59835 may expose scanning virtual-machine VNC services
HIGH
CVE-2026-59835 is an exposure-of-resource-to-wrong-sphere vulnerability affecting FortiSandbox 5.0.0 through 5.0.2 and 4.4.3 through 4.4.8. It may allow an unauthenticated attacker to access the VNC server of virtual machines performing scans by sending network requests.
05
CVE-2026-8590 affects multiple server deployment lines
HIGH
CVE-2026-8590 affects Spotfire Server modules in Spotfire Enterprise, Spotfire Enterprise with External Consumers and Spotfire on Kubernetes.
06
Eight CVEs include actively exploited CVE-2025-31277
HIGH
This advisory retains CVE-2025-24119, CVE-2025-24188, CVE-2025-24224, CVE-2025-31243, CVE-2025-31273, CVE-2025-31275, CVE-2025-31277 and CVE-2025-31278.
07
W3C baggage parsing can cause denial of service across six tracer CVEs
HIGH
CVE-2026-50270, CVE-2026-50271, CVE-2026-50272, CVE-2026-50273, CVE-2026-50274 and CVE-2026-50276 describe remote, unauthenticated denial-of-service exposure in Datadog tracing libraries.
08
CVE-2026-59831 can permit command execution through a malicious Codespace
MEDIUM
GitHub CLI versions 2.10.0 through 2.95.0 can permit command execution when a user connects to a malicious Codespace with gh codespace jupyter. The command opens a JupyterLab URL supplied by a process inside the Codespace without verifying that it is a loopback HTTP or HTTPS address.
09
Chrome 150 and Firefox 152 updates address vulnerabilities with public exploit code
INFO
SecurityWeek reports that Chrome 150 and Firefox 152 updates resolve vulnerabilities described by the source as critical. Public exploit code targeting Firefox flaws exists, but the captured source states that no in-the-wild exploitation of those Firefox flaws had been observed.
10
CISA reports active exploitation against internet-exposed SharePoint servers
INFO
The source reports that CISA warned of attackers actively exploiting three vulnerabilities to compromise internet-exposed, on-premises SharePoint Server instances.
11
Microsoft releases July 2026 updates for 622 vulnerabilities
INFO
CrowdStrike reports that Microsoft released security updates for 622 vulnerabilities in its July 2026 Patch Tuesday rollout. Its headline states that the release includes two exploited zero-days.
12
Progress associates a ShareFile zero-day with a Storage Zone shutdown
INFO
Progress Software confirmed that a high-severity zero-day vulnerability was behind the emergency shutdown of ShareFile Storage Zone Controllers and released security updates to patch the flaw. This preserves the source's association and does not establish that the vulnerability caused the shutdown.

What changed

Finding 01 records a patch release for critical CVE-2026-44747. The vulnerability is an out-of-bounds write in SAP NetWeaver Application Server ABAP that an authenticated attacker could use to corrupt memory, potentially leading to unauthorised data access, modification or system unavailability.

Finding 02 introduces critical CVE-2025-11698. The reported issue affects 5380, 5480 and 5580 controllers running boot firmware below 1.072 and could allow invalid file data to place a controller into a major non-recoverable fault.

Finding 03 adds eight Pillow-related vulnerabilities: CVE-2020-35653, CVE-2020-35655, CVE-2021-25287, CVE-2021-25288, CVE-2021-25290, CVE-2021-25292, CVE-2021-25293 and CVE-2021-27921. The available description specifically identifies a buffer over-read in PcxDecode before Pillow 8.1.0 when processing a crafted PCX file.

Finding 04 identifies high-severity CVE-2026-59835 in FortiSandbox 5.0.0 through 5.0.2 and 4.4.3 through 4.4.8. Network requests may allow an unauthenticated attacker to access the VNC server of virtual machines performing scans.

Finding 05 adds high-severity CVE-2026-8590 across specified Spotfire Enterprise, Spotfire Enterprise with External Consumers and Spotfire on Kubernetes release lines.

Finding 06 adds CVE-2025-24119, CVE-2025-24188, CVE-2025-24224, CVE-2025-31243, CVE-2025-31273, CVE-2025-31275, CVE-2025-31277 and CVE-2025-31278. CVE-2025-31277 has verified active exploitation through its CISA Known Exploited Vulnerabilities listing, overriding the aggregate indication that exploitation was not confirmed.

Finding 07 introduces high-severity CVE-2026-50270, CVE-2026-50271, CVE-2026-50272, CVE-2026-50273, CVE-2026-50274 and CVE-2026-50276. GitHub advisories describe remote, unauthenticated denial-of-service exposure where Datadog tracing libraries parse W3C baggage headers without extraction-side item or byte limits.

Finding 08 introduces medium-severity CVE-2026-59831. GitHub CLI versions 2.10.0 through 2.95.0 may permit command execution when gh codespace jupyter connects to a malicious Codespace; the description states that version 2.96.0 fixes the issue.

Finding 09 reports Chrome 150 and Firefox 152 updates resolving vulnerabilities described by the source as critical, including Firefox issues for which public exploit code exists. The same source excerpt says no in-the-wild exploitation of those Firefox flaws had been observed.

Finding 10 reports that CISA warned of attackers actively exploiting three vulnerabilities against internet-exposed, on-premises SharePoint Server instances.

Finding 11 reports that Microsoft released security updates for 622 vulnerabilities in its July 2026 Patch Tuesday rollout. The source headline identifies two exploited zero-days, but the available details do not identify them.

Finding 12 reports that Progress Software associated a high-severity zero-day vulnerability with the emergency shutdown of ShareFile Storage Zone Controllers and released security updates for the flaw. This association must not be interpreted as proof that the vulnerability caused the shutdown.

Why it matters

Finding 01 presents a direct confidentiality, integrity and availability risk to authenticated SAP NetWeaver Application Server ABAP environments, with a patch now reported as available.

Finding 02 could make affected industrial controllers unavailable by placing them into a major non-recoverable fault, while Finding 04 could expose access to the VNC servers of scanning virtual machines. These are distinct operational risks and require separate product-specific responses.

Finding 03 matters where untrusted PCX files can reach Pillow-based processing, while Finding 07 matters where unauthenticated requests can supply W3C baggage headers to affected tracing libraries. Both can affect availability, but their mechanisms and affected software are different.

Finding 05 spans several Spotfire deployment models, making accurate version inventory important. Finding 08 requires a user to connect to a malicious Codespace, but can then allow command execution through an unvalidated JupyterLab URL.

Finding 06 warrants priority because CVE-2025-31277 has verified active exploitation. The source also states that an application may be able to execute arbitrary code outside its sandbox or with certain elevated privileges.

Finding 09 includes public exploit code without observed in-the-wild exploitation in the captured source, whereas Finding 10 reports active exploitation against internet-exposed SharePoint Server instances. These exploitation statements are specific to their respective findings and must not be transferred to other products.

Finding 11 represents an unusually large Microsoft update set, but the available excerpt does not establish which products or vulnerabilities carry the greatest operational risk. Finding 12 is more narrowly actionable because the source associates a zero-day with ShareFile Storage Zone Controllers and reports that security updates are available.

  • Recommended actions
  • SAP platform owner: For Finding 01, identify deployments corresponding to SAP NetWeaver Application Server ABAP, verify applicability of CVE-2026-44747 against the linked report and apply the available SAP update through the organisation's change process.
  • Industrial control owner: For Finding 02, inventory 5380, 5480 and 5580 controllers, identify units running boot firmware below 1.072 and consult the linked advisory for the applicable remediation because patch status is not established here.
  • Application and Linux owner: For Finding 03, locate Pillow use, prioritise services that process untrusted PCX files and verify affected package versions and supported updates through the linked advisory. Do not treat the recorded upstream commit identifiers as confirmation that a deployable package update has been installed.
  • Security appliance owner: For Finding 04, identify FortiSandbox 5.0.0 through 5.0.2 and 4.4.3 through 4.4.8 deployments, review whether their scanning-VM VNC services are reachable by untrusted network clients and obtain the exact remediation from the linked advisory.
  • Analytics platform owner: For Finding 05, compare deployed Spotfire Enterprise, External Consumers and Kubernetes versions individually with the affected versions in the linked advisory, then confirm the appropriate update or mitigation for each deployment.
  • Endpoint owner: For Finding 06, prioritise verification of CVE-2025-31277 because active exploitation is confirmed. Confirm that relevant systems have reached macOS Sequoia 15.3, Sonoma 14.7.7 or Ventura 13.7.7 as applicable, and review the linked advisory for the other seven CVEs separately.
  • Observability owner: For Finding 07, inventory affected Datadog tracing libraries, identify services that accept W3C baggage headers from unauthenticated clients and use each linked GitHub advisory to establish the affected and remediated version for its corresponding CVE.
  • Developer tooling owner: For Finding 08, upgrade GitHub CLI installations used with Codespaces to version 2.96.0 or later and warn users not to run gh codespace jupyter against untrusted Codespaces before the upgrade.
  • Browser owner: For Finding 09, verify deployment of Chrome 150 and Firefox 152 updates. Use the linked report to identify the underlying vulnerabilities because the available information does not provide their CVE identifiers or affected subversions.
  • Collaboration platform owner: For Finding 10, identify internet-exposed on-premises SharePoint Server instances and follow CISA's referenced patching direction after confirming the three vulnerability identifiers and applicable versions in the linked report.
  • Microsoft estate owner: For Finding 11, reconcile the July 2026 Patch Tuesday release against the organisation's Microsoft product inventory and use Microsoft's product-specific guidance to determine priority. The available excerpt does not support treating all 622 vulnerabilities as equivalent.
  • File-transfer service owner: For Finding 12, identify ShareFile Storage Zone Controllers, consult the linked report for affected versions and deploy the released security updates where applicable. Do not infer that the vulnerability caused the emergency shutdown; the source describes it as being behind the shutdown.

Evidence limits

Finding 01 does not provide structured affected-product data or confirmed exploitation. Finding 02 has a severity conflict: the source narrative labels it high, while the technical decision is Critical; exploitation is not confirmed and patch status is unknown.

Finding 03, Finding 04, Finding 05 and Finding 07 do not have confirmed exploitation or an established overall patch state. Their affected products or versions must be verified through their respective linked advisories rather than inferred from another finding.

Finding 06 has an aggregate exploitation value that does not reflect the per-CVE evidence for CVE-2025-31277. That CVE is actively exploited according to CISA KEV; exploitation is not confirmed for CVE-2025-24119, CVE-2025-24188, CVE-2025-24224, CVE-2025-31243, CVE-2025-31273, CVE-2025-31275 or CVE-2025-31278. The source prose names fixed macOS releases, but the overall patch-state field remains unknown.

Finding 08 has a severity conflict: the narrative calls CVE-2026-59831 high severity, while the technical decision is Medium. The prose states that version 2.96.0 fixes the issue, but the overall patch-state field is unknown and exploitation is not confirmed.

Finding 09, Finding 10, Finding 11 and Finding 12 lack grounded severity, structured affected-product data and established patch or exploitation states. Their source prose supplies narrower observations, including public exploit code without observed exploitation in Finding 09, reported active exploitation in Finding 10, a headline reference to two exploited zero-days in Finding 11 and released ShareFile updates in Finding 12; none of those observations should be generalised beyond its own finding.

cve-2020-35653cve-2025-11698cve-2025-31277cve-2026-44747cve-2026-50270cve-2026-59831cve-2026-59835cve-2026-8590

Act on this brief

Map detection coverage gaps for the techniques above, or generate Sigma rules from the named CVEs.