---
schema: 1
kind: vulnerability
title: "CVE-2026-44748 — SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8)"
headline: "CVE-2026-44748 — SAP June Patch Day: SAML XML Signature Wrapping in NetWeaver AS ABAP (CVSS 9.9) plus an unauth RFC kernel memory-corruption (CVSS 9.8)"
summary: "Heavy CH/EU public-sector patch load lands at once: SAP June Patch Day (CVE-2026-44748 SAML XML Signature Wrapping, CVSS 9.9, in NetWeaver AS ABAP), a strongSwan pre-auth double-free RCE (CVE-2026-47895), and a 13-CVE TYPO3 core release spanning every supported branch (NCSC-CH, 2026-06-09)."
discovered_at: "2026-06-10T05:00:06Z"
event_date: 2026-06-09
run_id: 2026-06-10-c84347b2
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - auth-bypass
  - identity
regions:
  - switzerland
  - europe
  - global
sectors:
  - public-sector
entities: []
cves:
  - id: CVE-2026-44748
    cvss: "9.9"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-27671
    cvss: "9.8"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-40128
    cvss: "9.0"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-22732
    cvss: "9.1"
    epss: null
    type: auth-bypass
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://onapsis.com/blog/sap-security-patch-day-june-2026"
    publisher: "Onapsis, 2026-06-09"
    role: primary
  - url: "https://security-hub.ncsc.admin.ch/#/posts/12620"
    publisher: "NCSC-CH, 2026-06-09"
    role: corroborating
  - url: "https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2026.html"
    publisher: "SAP, 2026-06-09"
    role: corroborating
  - url: "https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/"
    publisher: "BleepingComputer, 2026-06-09"
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions:
  - "**Sequence the CH/EU public-sector patch load by exposure:** SAP June notes (CVE-2026-44748 SAML XSW + CVE-2026-27671 unauth RFC kernel) with RFC gateway ACLs enabled; strongSwan 6.0.7 (CVE-2026-47895 pre-auth RCE) on IKEv2/EAP VPN gateways; TYPO3 13.4.31 / 14.3.3 on public-facing CMS estates; Veeam 12.3.2.4854 (CVE-2026-44963) on domain-joined backup servers."
migrated_from: briefs/2026-06-10.md
---

SAP's June Patch Day (9 June) shipped multiple HotNews notes; the most severe affect NetWeaver AS ABAP and ABAP Platform — the ERP backbone across Swiss federal/cantonal administration and EU public-sector bodies ([Onapsis, 2026-06-09](https://onapsis.com/blog/sap-security-patch-day-june-2026)). CVE-2026-44748 (CVSS 9.9) is an XML Signature Wrapping flaw in the SAML authentication handler: an attacker takes a legitimately-signed SAML assertion and replaces the processed element with attacker-controlled identity data while leaving the signature valid, enabling privilege escalation/account takeover. It spans SAP_BASIS 702–919, an unusually broad patch footprint ([NCSC-CH, 2026-06-09](https://security-hub.ncsc.admin.ch/#/posts/12620)). CVE-2026-27671 (CVSS 9.8) is memory corruption via improper RFC protocol validation reachable unauthenticated over the network; CVE-2026-40128 (CVSS 9.0) is a path traversal in the NetWeaver AS Java Web Container; CVE-2026-22732 (CVSS 9.1) is a missing-security-headers bug in Spring Security affecting Commerce Cloud/Data Hub ([SAP, 2026-06-09](https://support.sap.com/en/my-support/knowledge-base/security-notes-news/june-2026.html)). Exploitation is listed UNKNOWN for all four. Apply the June SAP Security Notes (SAP Note 3746332 is the SAML XSW fix for CVE-2026-44748) and enable RFC gateway ACLs (`gw/acl_mode=1`) and SNC to reduce the RFC-kernel exposure. CCB Belgium issued a parallel public-sector "patch now" advisory ([CCB, 2026-06-09](https://ccb.belgium.be/advisories/warning-sap-addresses-critical-vulnerabilities-affecting-multiple-sap-products-patch)).
