Vulnerability intelligence
CVE-2026-27690
Due to an HTTP Request Smuggling vulnerability in SAP Approuter, an unauthenticated attacker could send a specially crafted HTTP request that leads to request-response desynchronization. This could result in the exposure of user responses and cause the system to become unavailable. This leads to a high impact on confidentiality and availability.
CVSS Score
9.1
Critical
EPSS — Exploit Probability
0.7%
Riskier than 50% of all CVEs
Exploitation
Not in CISA KEV
No federal exploitation record
Remediation
unknown
Check vendor advisories
2 articles across 2 outlets · first covered Jul 14, 2026 · latest Jul 14, 2026
Tracked incidents
Coverage timeline
-
SAP patches memory corruption flaw in NetWeaver after Patch Daywww.securityweek.com · Jul 14, 2026
-
SAP July 2026 Patch Tackles NetWeaver Memory Corruption Bugsecurityonline.info · Jul 14, 2026