Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
Key Takeaways SAP’s August 2026 Security Patch Day addresses 28 new vulnerabilities, including several critical flaws. Impacted systems include SAP Commerce Cloud, SAP NetWeaver, ABAP Platform,...
Key Takeaways
- SAP’s August 2026 Security Patch Day addresses 28 new vulnerabilities, including several critical flaws.
- Impacted systems include SAP Commerce Cloud, SAP NetWeaver, ABAP Platform, and SAP Manufacturing Integration and Intelligence.
- Critical vulnerabilities, some with a CVSS score of 10.0, could enable unauthenticated code injection, memory corruption, and privilege escalation.
- Immediate patching is strongly recommended for all affected enterprise SAP deployments due to the severity and potential for remote exploitation.
SAP Unveils Critical Patches Addressing Major Vulnerabilities in Core Business Platforms
SAP has released its August 2026 Security Patch Day, a significant update package that delivers fixes for 28 new security notes, alongside one GitHub security advisory and two updates to previously issued notes. The patches, made available on August 11, 2026, target several critical-severity flaws that could allow unauthenticated attackers to execute malicious code, corrupt system memory, and escalate privileges across widely used enterprise platforms.
Table Of Content
Given the pervasive reliance of global enterprises on SAP systems for critical functions like enterprise resource planning, finance, supply chain management, and commerce, cybersecurity teams are urged to prioritize the immediate deployment of these updates.
Severe Vulnerabilities Threaten Core SAP Operations
Among the most pressing issues addressed this month is an improper authorization vulnerability in the Data Hub Adapter component of SAP Commerce Cloud. Identified as CVE-2026-58231, this flaw has been assigned a maximum CVSS score of 10.0. It specifically affects COM_CLOUD versions 2211 and 2211-JDK21. The highest severity rating indicates that exploiting this vulnerability requires no prior authentication or user interaction, potentially granting remote attackers full control over the confidentiality, integrity, and availability of affected systems.
Another critical vulnerability involves a code injection flaw within SAP Manufacturing Integration and Intelligence. Tracked as CVE-2026-44772, this issue holds a CVSS score of 9.9. Successful exploitation of this vulnerability, which impacts XMII and MII_ADMIN versions 15.4 and 15.5, could allow adversaries to execute arbitrary code within essential manufacturing software environments. A related code injection vulnerability in the same component, CVE-2026-44758, also rates as critical with a CVSS score of 9.1.
Memory Corruption Risks and Broader Impacts
Memory corruption vulnerabilities are also a significant concern in this patch cycle. CVE-2026-34265, with a CVSS score of 9.8, addresses a severe memory corruption flaw affecting the Application Server ABAP component within SAP NetWeaver and the ABAP Platform. This vulnerability impacts a broad spectrum of kernel versions, from 7.22 up to the more recent 9.19 releases.
Memory corruption flaws in foundational application servers are particularly dangerous because they can be weaponized by attackers to achieve remote code execution, providing initial access that can then be used to pivot and move laterally across corporate networks. Organizations must apply these critical SAP patches promptly to prevent threat actors from developing and deploying reliable exploit chains.
As detailed in the official SAP August 2026 Security Patch Day advisory, enterprise systems are under constant threat from sophisticated cyberattack groups. Applying these security updates is crucial to prevent adversaries from exploiting unpatched infrastructure or leveraging vulnerabilities like SQL injection against critical business databases.
| SAP Note / Advisory | CVE | Vulnerability | Affected Product | CVSS |
|---|---|---|---|---|
| 3771065 | CVE-2026-58231 | Improper authorization | SAP Commerce Cloud (Data Hub Adapter), COM_CLOUD 2211 / 2211-JDK21 | 10.0 |
| 3765948 | CVE-2026-44772 | Code injection | SAP Manufacturing Integration and Intelligence; XMII and MII_ADMIN 15.4 / 15.5 | 9.9 |
| 3714806 | CVE-2026-34265 | Memory corruption | SAP NetWeaver and ABAP Platform; affected kernel versions 7.22–9.19 | 9.8 |
| 3758900 | CVE-2026-44758 | Code injection | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 9.1 |
| 3772411 | CVE-2026-58243 | Privilege escalation | SAP ABAP Developer Tools; SAP_BASIS 750–758, 816, 918, 920 | 8.8 |
| 3773203 | CVE-2026-42945 | Potential buffer overflow | SAP Commerce Cloud public-cloud deployments with NGINX | 8.1 |
| 3756565 | CVE-2026-66763 | Credentials disclosure | SAP BusinessObjects BI Platform (Central Management Server) | 7.9 |
| 3727078 | CVE-2026-58233 | Remote code execution; updated July 2026 note | SAP Change and Transport System Attach Tool (ctsattach), CTS_UPLOAD_CLT 1 | 7.6 |
| 3759854 | CVE-2026-44763 | Directory traversal | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.6 |
| 3758657 | CVE-2026-44765 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.3 |
| 3758910 | CVE-2026-44764 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 7.3 |
| 3786038 | CVE-2026-58230 and 10 related CVEs | Multiple vulnerabilities | SAP Business AI Platform (Approuter), versions earlier than 23.0.0 | 7.0 |
| 3753141 | CVE-2026-58248 | XML external entity injection | SAP BusinessObjects Business Intelligence | 6.5 |
| 3770868 | CVE-2026-34480 | Improper output encoding in Apache Log4j Core | SAP Commerce Cloud and SAP Data Hub | 6.5 |
| 3757815 | CVE-2026-5598 | Potential information disclosure in Bouncy Castle Java library | SAP Commerce Cloud | 6.5 |
| 3721424 | CVE-2026-66779 | Cross-site scripting | SAP NetWeaver Application Server ABAP | 6.3 |
| 3766473 | CVE-2026-66770 | SQL injection | SAP Social Intelligence; S4FND 102–109 | 6.3 |
| 3758318 | CVE-2026-58235 | Vulnerable third-party component | SAP NetWeaver AS Java (Adobe Document Services) | 6.3 |
| 3772071 | CVE-2026-66771 | Cross-site scripting | SAPUI5 | 6.1 |
| GHSA-hc5j-q32w-c25v | CVE-2026-66773 | Server-controlled __next URL lacks cross-origin validation |
pyodata Python package, versions earlier than 1.11.2 | 5.9 |
| 3745182 | CVE-2026-58236 | OS command injection | SAP NetWeaver Application Server ABAP and ABAP Platform | 5.5 |
| 3540688 | CVE-2025-42947 | Code injection; updated July 2025 note | SAP FICA ODN Framework | 5.5 |
| 3725940 | CVE-2026-40130 | Memory corruption | SAPSPrint Service, SAPSPRINT 8.00 / 8.10 | 5.3 |
| 3756674 | CVE-2026-58247 | Memory corruption | SAP ABAP Platform; selected kernel 7.53–7.77 versions | 5.3 |
| 3778462 | CVE-2026-33871, CVE-2025-58057 | Multiple vulnerabilities | SAP Commerce Cloud Search and Navigation | 4.8 |
| 3669608 | CVE-2026-66764 | Missing authorization check | SAP S/4HANA Reprocess Bank Statement Items | 4.3 |
| 3770649 | CVE-2026-66772 | Missing authorization check | SAP BusinessObjects BI Platform Admin Tools; also listed for S/4HANA | 4.3 |
| 3781137 | CVE-2026-58244 | Missing authorization check | SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 | 4.3 |
| 3752864 | CVE-2026-58241 | Missing authorization check | SAP NetWeaver and ABAP Platform Change and Transport System wizard | 4.2 |
| 3763028 | CVE-2026-58245 | Hard-coded credentials | SAP Advanced Planning and Optimization Model Mix Planning | 3.8 |
| 3739913 | CVE-2026-44762 | Security misconfiguration | SAP Data Services Management Console | 3.7 |
Beyond the critical-rated bugs, several high-severity issues also necessitate immediate attention:
- Privilege Escalation (CVE-2026-58243): This vulnerability, scoring 8.8, affects a wide array of
SAP_BASISversions within SAP ABAP Developer Tools. - Public-Cloud Buffer Overflow (CVE-2026-42945): With a CVSS score of 8.1, this flaw impacts SAP Commerce Cloud environments that utilize NGINX in public-cloud configurations.
- CTS Attach Tool RCE (CVE-2026-58233): SAP has provided updated guidance for a remote code execution vulnerability in the Change and Transport System Attach Tool (
ctsattach), which was initially disclosed in July 2026. - Additional High-Severity Notes: These include vulnerabilities leading to credential disclosure in the SAP BusinessObjects Business Intelligence Platform, as well as directory traversal and missing authorization checks in Manufacturing Integration and Intelligence.
The remaining medium and low-severity notes address a diverse range of flaws across various SAP modules. These encompass cross-site scripting (XSS) vulnerabilities in SAPUI5 and NetWeaver Application Server ABAP, SQL injection in SAP Social Intelligence, XML External Entity (XXE) injection in BusinessObjects, a vulnerability in the pyodata Python library (GHSA-hc5j-q32w-c25v), and an information disclosure issue in the Bouncy Castle Java library used by Commerce Cloud.
Considering the extensive range of affected products, including NetWeaver, ABAP Platform, Commerce Cloud, BusinessObjects, and Manufacturing Integration and Intelligence, security administrators must prioritize applying these SAP security updates without delay.
What You Should Do
- Identify Exposed Instances: Conduct a comprehensive inventory of all public-facing and internal SAP deployments running Commerce Cloud, NetWeaver, or Manufacturing Integration and Intelligence.
- Prioritize Critical Notes: Immediately apply patches for CVE-2026-58231, CVE-2026-44772, and CVE-2026-34265, treating this as an emergency maintenance task.
- Audit Developer Tools: Ensure all
SAP_BASISmodules are updated to mitigate privilege escalation risks in developer environments. - Verify Third-Party Libraries: Confirm that underlying dependencies, such as the
pyodataPython package and the Bouncy Castle Java library, are updated across all custom application extensions.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.