SAP’s August 2026 Security Patch Day has delivered a substantial round of fixes, addressing 28 new security notes and one GitHub security advisory, alongside two updates to previously released notes.
Released on August 11, 2026, this patch batch mitigates several critical-severity flaws that could allow unauthenticated attackers to inject malicious code, corrupt system memory, and escalate privileges across widely deployed enterprise platforms.
Given the extensive enterprise reliance on SAP systems for enterprise resource planning, finance, supply chain, and commerce operations, security teams are strongly advised to treat this update cycle as an emergency priority.
Critical SAP Vulnerabilities Enable Malicious Code Injection
The most alarming issue resolved this month is an improper authorization vulnerability in SAP Commerce Cloud’s Data Hub Adapter. Tracked as CVE-2026-58231, the flaw carries a maximum CVSS score of 10.0 and affects COM_CLOUD versions 2211 and 2211-JDK21.
Its maximum severity rating indicates that exploitation requires no prior privileges or user interaction, granting remote attackers complete control over confidentiality, integrity, and availability.
Following closely is a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence, designated as CVE-2026-44772 with a CVSS score of 9.9.
Impacting XMII and MII_ADMIN versions 15.4 and 15.5, successful exploitation allows adversaries to execute arbitrary code within production-critical manufacturing software.
A second code injection bug in the same component, CVE-2026-44758 (CVSS 9.1), rounds out the critical tier.
Memory corruption risks also feature prominently in this release cycle. Tracked as CVE-2026-34265 with a CVSS score of 9.8, a severe memory corruption bug impacts the Application Server ABAP component within SAP NetWeaver and the ABAP Platform.
The vulnerability spans a wide range of kernel versions, from 7.22 up to the modern 9.19 releases.
Memory corruption flaws in core application servers are particularly dangerous because adversaries can weaponize them to achieve remote code execution, establishing initial access to pivot laterally across corporate networks.
Mitigating such systemic memory issues requires organizations to patch critical SAP vulnerabilities before threat actors build reliable exploit chains.
As outlined in the official SAP August 2026 Security Patch Day advisory, enterprise systems face continuous targeting from sophisticated threat groups. Applying these patches prevents adversaries from weaponizing unpatched infrastructure or leveraging SQL injection flaws against core business databases.
| SAP Note / Advisory | CVE | Vulnerability | Affected Product | CVSS |
|---|---|---|---|---|
| 3771065 | CVE-2026-58231 | Improper authorization | SAP Commerce Cloud (Data Hub Adapter), COM_CLOUD 2211 / 2211-JDK21 | 10.0 |
| 3765948 | CVE-2026-44772 | Code injection | SAP Manufacturing Integration and Intelligence; XMII and MII_ADMIN 15.4 / 15.5 | 9.9 |
| 3714806 | CVE-2026-34265 | Memory corruption | SAP NetWeaver and ABAP Platform; affected kernel versions 7.22–9.19 | 9.8 |
| 3758900 | CVE-2026-44758 | Code injection | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 9.1 |
| 3772411 | CVE-2026-58243 | Privilege escalation | SAP ABAP Developer Tools; SAP_BASIS 750–758, 816, 918, 920 | 8.8 |
| 3773203 | CVE-2026-42945 | Potential buffer overflow | SAP Commerce Cloud public-cloud deployments with NGINX | 8.1 |
| 3756565 | CVE-2026-66763 | Credentials disclosure | SAP BusinessObjects BI Platform (Central Management Server) | 7.9 |
| 3727078 | CVE-2026-58233 | Remote code execution; updated July 2026 note | SAP Change and Transport System Attach Tool (ctsattach), CTS_UPLOAD_CLT 1 | 7.6 |
| 3759854 | CVE-2026-44763 | Directory traversal | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.6 |
| 3758657 | CVE-2026-44765 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.3 |
| 3758910 | CVE-2026-44764 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.3 |
| 3786038 | CVE-2026-58230 and 10 related CVEs | Multiple vulnerabilities | SAP Business AI Platform (Approuter), versions earlier than 23.0.0 | 7.0 |
| 3753141 | CVE-2026-58248 | XML external entity injection | SAP BusinessObjects Business Intelligence | 6.5 |
| 3770868 | CVE-2026-34480 | Improper output encoding in Apache Log4j Core | SAP Commerce Cloud and SAP Data Hub | 6.5 |
| 3757815 | CVE-2026-5598 | Potential information disclosure in Bouncy Castle Java library | SAP Commerce Cloud | 6.5 |
| 3721424 | CVE-2026-66779 | Cross-site scripting | SAP NetWeaver Application Server ABAP | 6.3 |
| 3766473 | CVE-2026-66770 | SQL injection | SAP Social Intelligence; S4FND 102–109 | 6.3 |
| 3758318 | CVE-2026-58235 | Vulnerable third-party component | SAP NetWeaver AS Java (Adobe Document Services) | 6.3 |
| 3772071 | CVE-2026-66771 | Cross-site scripting | SAPUI5 | 6.1 |
| GHSA-hc5j-q32w-c25v | CVE-2026-66773 | Server-controlled __next URL lacks cross-origin validation | pyodata Python package, versions earlier than 1.11.2 | 5.9 |
| 3745182 | CVE-2026-58236 | OS command injection | SAP NetWeaver Application Server ABAP and ABAP Platform | 5.5 |
| 3540688 | CVE-2025-42947 | Code injection; updated July 2025 note | SAP FICA ODN Framework | 5.5 |
| 3725940 | CVE-2026-40130 | Memory corruption | SAPSPrint Service, SAPSPRINT 8.00 / 8.10 | 5.3 |
| 3756674 | CVE-2026-58247 | Memory corruption | SAP ABAP Platform; selected kernel 7.53–7.77 versions | 5.3 |
| 3778462 | CVE-2026-33871, CVE-2025-58057 | Multiple vulnerabilities | SAP Commerce Cloud Search and Navigation | 4.8 |
| 3669608 | CVE-2026-66764 | Missing authorization check | SAP S/4HANA Reprocess Bank Statement Items | 4.3 |
| 3770649 | CVE-2026-66772 | Missing authorization check | SAP BusinessObjects BI Platform Admin Tools; also listed for S/4HANA | 4.3 |
| 3781137 | CVE-2026-58244 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 4.3 |
| 3752864 | CVE-2026-58241 | Missing authorization check | SAP NetWeaver and ABAP Platform Change and Transport System wizard | 4.2 |
| 3763028 | CVE-2026-58245 | Hard-coded credentials | SAP Advanced Planning and Optimization Model Mix Planning | 3.8 |
| 3739913 | CVE-2026-44762 | Security misconfiguration | SAP Data Services Management Console | 3.7 |
Beyond the critical-rated bugs, several high-severity issues demand immediate remediation:
- Privilege Escalation (CVE-2026-58243): Scores 8.8 and affects a broad range of
SAP_BASISversions inside SAP ABAP Developer Tools. - Public-Cloud Buffer Overflow (CVE-2026-42945): Scores 8.1 and impacts SAP Commerce Cloud environments running NGINX in public-cloud configurations.
- CTS Attach Tool RCE (CVE-2026-58233): Updated guidance for a remote code execution flaw in the Change and Transport System Attach Tool (
ctsattach), originally disclosed in July 2026. - Additional High-Severity Notes: Cover credential disclosure in the SAP BusinessObjects Business Intelligence Platform, as well as directory traversal and missing authorization checks in Manufacturing Integration and Intelligence.
The medium and low-severity notes address a broad spectrum of flaws across various modules.
These include cross-site scripting (XSS) in SAPUI5 and NetWeaver Application Server ABAP, SQL injection in SAP Social Intelligence, XML External Entity (XXE) injection in BusinessObjects, a vulnerable pyodata Python library flaw (GHSA-hc5j-q32w-c25v), and an information disclosure issue in the Bouncy Castle Java library utilized by Commerce Cloud.
Due to the wide footprint of impacted products including NetWeaver, ABAP Platform, Commerce Cloud, BusinessObjects, and Manufacturing Integration and Intelligence security administrators must prioritize applying these SAP security updates immediately.
- Identify Exposed Instances: Inventory all public-facing and internal SAP deployments running Commerce Cloud, NetWeaver, or MII.
- Prioritize Critical Notes: Apply patches for CVE-2026-58231, CVE-2026-44772, and CVE-2026-34265 on an emergency maintenance schedule.
- Audit Developer Tools: Update
SAP_BASISmodules to resolve privilege escalation risks in developer environments. - Verify Third-Party Libraries: Ensure underlying dependencies like
pyodataand Bouncy Castle are updated across custom app extensions.
[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now
