Tuesday, September 15, 2026
Follow on LinkedIn

Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory

SAP’s August 2026 Security Patch Day has delivered a substantial round of fixes, addressing 28 new security notes and one GitHub security advisory, alongside two updates to previously released notes.

Released on August 11, 2026, this patch batch mitigates several critical-severity flaws that could allow unauthenticated attackers to inject malicious code, corrupt system memory, and escalate privileges across widely deployed enterprise platforms.

Given the extensive enterprise reliance on SAP systems for enterprise resource planning, finance, supply chain, and commerce operations, security teams are strongly advised to treat this update cycle as an emergency priority.

Critical SAP Vulnerabilities Enable Malicious Code Injection

The most alarming issue resolved this month is an improper authorization vulnerability in SAP Commerce Cloud’s Data Hub Adapter. Tracked as CVE-2026-58231, the flaw carries a maximum CVSS score of 10.0 and affects COM_CLOUD versions 2211 and 2211-JDK21.

Its maximum severity rating indicates that exploitation requires no prior privileges or user interaction, granting remote attackers complete control over confidentiality, integrity, and availability.

Following closely is a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence, designated as CVE-2026-44772 with a CVSS score of 9.9.

Impacting XMII and MII_ADMIN versions 15.4 and 15.5, successful exploitation allows adversaries to execute arbitrary code within production-critical manufacturing software.

A second code injection bug in the same component, CVE-2026-44758 (CVSS 9.1), rounds out the critical tier.

Memory corruption risks also feature prominently in this release cycle. Tracked as CVE-2026-34265 with a CVSS score of 9.8, a severe memory corruption bug impacts the Application Server ABAP component within SAP NetWeaver and the ABAP Platform.

The vulnerability spans a wide range of kernel versions, from 7.22 up to the modern 9.19 releases.

Memory corruption flaws in core application servers are particularly dangerous because adversaries can weaponize them to achieve remote code execution, establishing initial access to pivot laterally across corporate networks.

Mitigating such systemic memory issues requires organizations to patch critical SAP vulnerabilities before threat actors build reliable exploit chains.

As outlined in the official SAP August 2026 Security Patch Day advisory, enterprise systems face continuous targeting from sophisticated threat groups. Applying these patches prevents adversaries from weaponizing unpatched infrastructure or leveraging SQL injection flaws against core business databases.

SAP Note / AdvisoryCVEVulnerabilityAffected ProductCVSS
3771065CVE-2026-58231Improper authorizationSAP Commerce Cloud (Data Hub Adapter), COM_CLOUD 2211 / 2211-JDK2110.0
3765948CVE-2026-44772Code injectionSAP Manufacturing Integration and Intelligence; XMII and MII_ADMIN 15.4 / 15.59.9
3714806CVE-2026-34265Memory corruptionSAP NetWeaver and ABAP Platform; affected kernel versions 7.22–9.199.8
3758900CVE-2026-44758Code injectionSAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.59.1
3772411CVE-2026-58243Privilege escalationSAP ABAP Developer Tools; SAP_BASIS 750–758, 816, 918, 9208.8
3773203CVE-2026-42945Potential buffer overflowSAP Commerce Cloud public-cloud deployments with NGINX8.1
3756565CVE-2026-66763Credentials disclosureSAP BusinessObjects BI Platform (Central Management Server)7.9
3727078CVE-2026-58233Remote code execution; updated July 2026 noteSAP Change and Transport System Attach Tool (ctsattach), CTS_UPLOAD_CLT 17.6
3759854CVE-2026-44763Directory traversalSAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.57.6
3758657CVE-2026-44765Missing authorization checkSAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.57.3
3758910CVE-2026-44764Missing authorization checkSAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.57.3
3786038CVE-2026-58230 and 10 related CVEsMultiple vulnerabilitiesSAP Business AI Platform (Approuter), versions earlier than 23.0.07.0
3753141CVE-2026-58248XML external entity injectionSAP BusinessObjects Business Intelligence6.5
3770868CVE-2026-34480Improper output encoding in Apache Log4j CoreSAP Commerce Cloud and SAP Data Hub6.5
3757815CVE-2026-5598Potential information disclosure in Bouncy Castle Java librarySAP Commerce Cloud6.5
3721424CVE-2026-66779Cross-site scriptingSAP NetWeaver Application Server ABAP6.3
3766473CVE-2026-66770SQL injectionSAP Social Intelligence; S4FND 102–1096.3
3758318CVE-2026-58235Vulnerable third-party componentSAP NetWeaver AS Java (Adobe Document Services)6.3
3772071CVE-2026-66771Cross-site scriptingSAPUI56.1
GHSA-hc5j-q32w-c25vCVE-2026-66773Server-controlled __next URL lacks cross-origin validationpyodata Python package, versions earlier than 1.11.25.9
3745182CVE-2026-58236OS command injectionSAP NetWeaver Application Server ABAP and ABAP Platform5.5
3540688CVE-2025-42947Code injection; updated July 2025 noteSAP FICA ODN Framework5.5
3725940CVE-2026-40130Memory corruptionSAPSPrint Service, SAPSPRINT 8.00 / 8.105.3
3756674CVE-2026-58247Memory corruptionSAP ABAP Platform; selected kernel 7.53–7.77 versions5.3
3778462CVE-2026-33871, CVE-2025-58057Multiple vulnerabilitiesSAP Commerce Cloud Search and Navigation4.8
3669608CVE-2026-66764Missing authorization checkSAP S/4HANA Reprocess Bank Statement Items4.3
3770649CVE-2026-66772Missing authorization checkSAP BusinessObjects BI Platform Admin Tools; also listed for S/4HANA4.3
3781137CVE-2026-58244Missing authorization checkSAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.54.3
3752864CVE-2026-58241Missing authorization checkSAP NetWeaver and ABAP Platform Change and Transport System wizard4.2
3763028CVE-2026-58245Hard-coded credentialsSAP Advanced Planning and Optimization Model Mix Planning3.8
3739913CVE-2026-44762Security misconfigurationSAP Data Services Management Console3.7

Beyond the critical-rated bugs, several high-severity issues demand immediate remediation:

  • Privilege Escalation (CVE-2026-58243): Scores 8.8 and affects a broad range of SAP_BASIS versions inside SAP ABAP Developer Tools.
  • Public-Cloud Buffer Overflow (CVE-2026-42945): Scores 8.1 and impacts SAP Commerce Cloud environments running NGINX in public-cloud configurations.
  • CTS Attach Tool RCE (CVE-2026-58233): Updated guidance for a remote code execution flaw in the Change and Transport System Attach Tool (ctsattach), originally disclosed in July 2026.
  • Additional High-Severity Notes: Cover credential disclosure in the SAP BusinessObjects Business Intelligence Platform, as well as directory traversal and missing authorization checks in Manufacturing Integration and Intelligence.

The medium and low-severity notes address a broad spectrum of flaws across various modules.

These include cross-site scripting (XSS) in SAPUI5 and NetWeaver Application Server ABAP, SQL injection in SAP Social Intelligence, XML External Entity (XXE) injection in BusinessObjects, a vulnerable pyodata Python library flaw (GHSA-hc5j-q32w-c25v), and an information disclosure issue in the Bouncy Castle Java library utilized by Commerce Cloud.

Due to the wide footprint of impacted products including NetWeaver, ABAP Platform, Commerce Cloud, BusinessObjects, and Manufacturing Integration and Intelligence security administrators must prioritize applying these SAP security updates immediately.

  1. Identify Exposed Instances: Inventory all public-facing and internal SAP deployments running Commerce Cloud, NetWeaver, or MII.
  2. Prioritize Critical Notes: Apply patches for CVE-2026-58231, CVE-2026-44772, and CVE-2026-34265 on an emergency maintenance schedule.
  3. Audit Developer Tools: Update SAP_BASIS modules to resolve privilege escalation risks in developer environments.
  4. Verify Third-Party Libraries: Ensure underlying dependencies like pyodata and Bouncy Castle are updated across custom app extensions.

[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now

Guru Baran
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Cyber Security Guide

Latest Cyber News

Expert Talks