DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:05:39ZSOURCES: 14CRITICAL: 26
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Confirmed: FortiBleed (CVE campaign + brute force) has produced ~86,644 verified… /// @MandiantThreats CRITICAL — FortiBleed is an active, industrialized credential-harvesting campaign, not a single CVE… /// @TalosSecurity CRITICAL — DragonForce ransomware (tracked as Hackledorb) deployed novel Go-based Backdoor.Turn… /// @vxunderground CRITICAL — The Gentlemen RaaS (admin: hastalamuerte/zeta88, ex-Qilin ArmCorp affiliate) has claimed… /// @MalwareHunterTeam CRITICAL — 24 billion record infostealer credential cluster discovered June 12 by Cybernews — 8.3TB…
26Critical Threats
20Active CVEs
13IOCs Tracked
6New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-44748PUBLISHED: 2026-06-09
CRITICALCVE-2026-44748

SAP NetWeaver SAML XML Signature Wrapping Authentication Bypass

VENDOR: SAP//PRODUCT: SAP NetWeaver Application Server ABAP and ABAP Platform
9.9
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

An XML Signature Wrapping (XSW) vulnerability (CWE-347) in SAP NetWeaver's SAML authentication stack allows an authenticated attacker with normal user privileges to obtain a valid signed SAML message, tamper with the XML document structure, and submit the modified assertion to the verifier — which accepts the forged identity. Successful exploitation enables unauthorized access to sensitive user data, privilege escalation, and potential disruption of enterprise SSO flows. No public exploit or active exploitation observed; Onapsis disclosed the attack flow as part of SAP's June 2026 Patch Day.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
LOW
User Interaction
NONE
Scope / Impact
CHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSAP_BASIS versions 702 through 919 (extremely wide version footprint)
  • https://www.securityweek.com/sap-patches-critical-netweaver-commerce-vulnerabilities/
  • https://socradar.io/blog/sap-security-patch-day-june-2026-cve-2026-44748/
  • https://cybersecuritynews.com/sap-security-patch-day-june/
  • https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn