cybersecuritySAPvulnerabilitypatch managementCanada

SAP warns of critical flaws in NetWeaver and Commerce Cloud

July 13, 2026

Back to all posts

Source: BleepingComputer

SAP, a leading enterprise software company, has issued a warning about critical vulnerabilities in its NetWeaver and Commerce Cloud products. These flaws could potentially allow unauthorized access, data theft, or system manipulation. The vulnerabilities (CVE-2021-31189 and CVE-2021-31190) affect multiple components of the software, including Java-based applications, Web Dynpro ABAP, and SAP GUI for Windows. Given the widespread use of SAP solutions in Canadian businesses, these vulnerabilities pose a significant risk to local organizations. The impacted versions range from NetWeaver 7.0 to 7.52 and Commerce Cloud version for Retail (1908 and later). To mitigate this threat, SAP urges users to install the provided patches immediately and regularly monitor their systems for any suspicious activities.
cybersecuritySAPvulnerabilitypatch managementCanada

Concerned about this threat to your business?

We help Canadian SMBs deploy the controls discussed in this article. Free 30-minute assessment — no obligation.

Book a free assessment