
Meet the Authors
SAP’s June 2026 Security Patch Day delivered 15 new Security Notes, including critical issues affecting SAP NetWeaver AS ABAP, ABAP Platform, SAP NetWeaver AS Java, SAP Commerce Cloud, and SAP Data Hub.
The highest-severity vulnerabilities concentrated around SAP trust layers, including SAML authentication, RFC communication, Java logon handling, cloud middleware, and authorization controls.
The June patch cycle also kept SAP developer supply chain risk in focus through an update to SAP Note 3747787 tied to the Mini Shai-Hulud software supply chain attack.
SAP’s June 2026 Security Patch Day delivered 15 new Security Notes, matching May’s volume but carrying a sharper risk profile.
They concentrated around the mechanisms SAP systems use to establish trust: SAML authentication, RFC communication, Java logon handling, cloud middleware, and authorization. The broader June patch cycle also kept developer supply chain risk in view through an update to SAP Note 3747787.
June’s release stands out because the highest-severity notes sit in foundational parts of the SAP landscape, even though the overall note count was in line with May.
ABAP Trust Mechanisms Carry the Sharpest Risk
June’s two highest-severity notes both affect SAP NetWeaver AS ABAP and ABAP Platform, but they reach the platform through different trust surfaces.
The first is XML Signature Wrapping in SAML Authentication (CVSS 9.9). Jonathan Stross, Senior Product Manager Cybersecurity R&I at Pathlock, described the flaw as broadly relevant wherever SAML is used for SAP authentication, adding that “in large estates, this is not an edge case; it is a core authentication control.” Layer Seven Security analysts similarly framed the issue around “the trust boundary between XML signature verification and SAML identity consumption,” making the risk relevant for environments that rely on single sign-on, federated identity, portal access, or Web Service Security.
The second is memory corruption in AS ABAP (CVSS 9.8). Stross placed this issue ahead of the higher-scored SAML note in its operational prioritization, arguing that the flaw “sits underneath many business controls” and represents a platform-level risk.
Layer Seven Security described it as a kernel-level RFC protocol handling vulnerability that can be triggered by an unauthenticated attacker through a crafted RFC request. Remediation also carries operational weight: the fix requires a kernel patch through SAP kernel archive updates, with no workaround available.
The June release asks SAP security teams to validate the trust paths that connect identity, communication, and access control across ABAP environments. A separate high-priority missing authorization check in AS ABAP (CVSS 7.1) adds to that pattern.
Java Exposure and Commerce Cloud Dependency Risk
The remaining critical notes extend June’s trust-layer pattern beyond ABAP.
SAP NetWeaver AS Java is affected by a directory traversal vulnerability in the Web Container (CVSS 9.0). The issue can be triggered through crafted HTTP logon requests, making external reachability a key factor in remediation priority.
Stross described the vulnerability as “a perimeter and trust-boundary issue,” while Layer Seven Security identified externally reachable SAP NetWeaver AS Java logon endpoints as the highest-priority remediation target.
SAP Commerce Cloud faces a separate but related problem. June included a Spring Security vulnerability affecting SAP Commerce Cloud and SAP Data Hub (CVSS 9.1), along with multiple Apache Tomcat vulnerabilities in SAP Commerce Cloud (CVSS 7.4). Both point to third-party middleware exposure rather than a narrow SAP application defect.
Gert-Jan Koster, SAP Security specialist at SecurityBridge, connected that pattern to a recurring Patch Day issue, noting that “every patch cycle, we see vulnerabilities come by that are based on the use of insecure third-party libraries.”
June also follows a high-severity Commerce Cloud note from May. Koster pointed to a carryover update involving SAP Commerce Cloud missing authentication check, originally released in May and updated in June with textual changes. The pattern does not make Commerce Cloud uniquely exposed across SAP, but it does show why Commerce Cloud remediation needs clear ownership, sequencing, and validation.
Koster also raised SAP Note 3747787, which SAP updated after another malicious npm package was identified in the Mini Shai-Hulud software supply chain attack.
The note is not one of the 15 new June Security Notes, but it belongs in the broader June risk picture because it affects malicious open-source packages in SAP Cloud Application Programming Model and MTA Build Tool. The update illustrates why SAP security teams need visibility into how SAP applications are built, extended, and deployed.
What This Means for SAPinsiders
- ABAP trust mechanisms need continued review. June’s SAML and RFC notes add to a 2026 pattern of issues affecting ABAP authentication, communication, and authorization controls. SAP teams may treat kernel patch levels, SAML configuration, and authorization checks as recurring review areas, rather than one-time Patch Day tasks.
- Commerce Cloud remediation may need separate coordination. June adds new Commerce Cloud exposure through Spring Security and Apache Tomcat, following a high-severity note from May. Because some fixes involve application deployment steps, remediation may need its own ownership, sequencing, and validation process.
- Supply chain risk can outlast the patch cycle. The Mini Shai-Hulud update is a reminder that developer tooling, credential stores, and build pipelines can remain in scope after first disclosure. SAP teams increasingly treat developer environment governance — including package controls, credential rotation, and build-pipeline monitoring — as part of their broader SAP security program.




