Critical severity9.0NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-40128
CVE-2026-40128
Description
SAP NetWeaver Application Server Java (Web Container) allows an unauthenticated attacker to craft a malicious HTTP logon request that manipulates file inclusion parameters, enabling path traversal and processing of the included file. Processing the included file could allow the attacker to view or modify sensitive information or render any part of the local system unavailable.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
7- SAP Security Update July 2026 – Patch for Critical SAP NetWeaver Flaw that Enables Memory CorruptionCyber Security News · Jul 14, 2026
- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News · Jun 15, 2026
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical VulnerabilitiesThe Hacker News · Jun 10, 2026
- SAP fixes critical flaws in NetWeaver and Commerce CloudBleepingComputer · Jun 9, 2026
- SAP Patches Critical NetWeaver, Commerce VulnerabilitiesSecurityWeek · Jun 9, 2026
- SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver PatchedCyber Security News · Jun 9, 2026
- SAP: Twelve Vulnerabilities Disclosed Together on June 9, 2026Vypr Intelligence · Jun 9, 2026