DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 05:07:52ZSOURCES: 14CRITICAL: 34
⚠ ACTIVE ALERTS
@AlvieriD CRITICAL — CORRELATED | Actor '888' listing on PwnForums: claims 35GB of Accenture source code,… /// @DarkWebInformer CRITICAL — CORRELATED | Prinz Eugen ransomware operation — actor ROOTBOY (aka avtokz / GERMANIA)… /// @MalwareHunterTeam CRITICAL — CORRELATED | PolinRider (DPRK / Famous Chollima / Contagious Interview) supply chain… /// @GossiTheDog CRITICAL — CORRELATED | CVE-2026-8037 Progress Kemp LoadMaster pre-auth RCE — exploitation attempts… /// @FalconFeedsio CRITICAL — CORRELATED | Tracking '888' forum listing for Accenture data (July 6, 2026). Dataset:…
34Critical Threats
19Active CVEs
10IOCs Tracked
7New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-44748PUBLISHED: 2026-06-09
CRITICALCVE-2026-44748

SAP NetWeaver SAML XML Signature Wrapping Authentication Bypass

VENDOR: SAP//PRODUCT: SAP NetWeaver Application Server ABAP and ABAP Platform
9.9
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

An XML Signature Wrapping (XSW) vulnerability (CWE-347) in SAP NetWeaver's SAML authentication stack allows an authenticated attacker with normal user privileges to obtain a valid signed SAML message, tamper with the XML document structure, and submit the modified assertion to the verifier — which accepts the forged identity. Successful exploitation enables unauthorized access to sensitive user data, privilege escalation, and potential disruption of enterprise SSO flows. No public exploit or active exploitation observed; Onapsis disclosed the attack flow as part of SAP's June 2026 Patch Day.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSAP_BASIS versions 702 through 919 (extremely wide version footprint)
  • https://www.securityweek.com/sap-patches-critical-netweaver-commerce-vulnerabilities/
  • https://socradar.io/blog/sap-security-patch-day-june-2026-cve-2026-44748/
  • https://cybersecuritynews.com/sap-security-patch-day-june/
  • https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn