Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Intel’s $20 Billion Stock Sale Sparks Debate on Chip Supply Chain Security
August 11, 2026
LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk
August 11, 2026
Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
August 11, 2026
Home/CyberSecurity News/Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption
CyberSecurity News

Critical SAP Vulnerabilities Allow Code Injection, Memory Corruption

Key Takeaways SAP’s August 2026 Security Patch Day addresses 28 new vulnerabilities, including several critical flaws. Impacted systems include SAP Commerce Cloud, SAP NetWeaver, ABAP Platform,...

Marcus Rodriguez
Marcus Rodriguez
August 11, 2026 5 Min Read
2 0

Key Takeaways

  • SAP’s August 2026 Security Patch Day addresses 28 new vulnerabilities, including several critical flaws.
  • Impacted systems include SAP Commerce Cloud, SAP NetWeaver, ABAP Platform, and SAP Manufacturing Integration and Intelligence.
  • Critical vulnerabilities, some with a CVSS score of 10.0, could enable unauthenticated code injection, memory corruption, and privilege escalation.
  • Immediate patching is strongly recommended for all affected enterprise SAP deployments due to the severity and potential for remote exploitation.

SAP Unveils Critical Patches Addressing Major Vulnerabilities in Core Business Platforms

SAP has released its August 2026 Security Patch Day, a significant update package that delivers fixes for 28 new security notes, alongside one GitHub security advisory and two updates to previously issued notes. The patches, made available on August 11, 2026, target several critical-severity flaws that could allow unauthenticated attackers to execute malicious code, corrupt system memory, and escalate privileges across widely used enterprise platforms.

Table Of Content

  • Key Takeaways
  • SAP Unveils Critical Patches Addressing Major Vulnerabilities in Core Business Platforms
  • Severe Vulnerabilities Threaten Core SAP Operations
  • Memory Corruption Risks and Broader Impacts
  • What You Should Do

Given the pervasive reliance of global enterprises on SAP systems for critical functions like enterprise resource planning, finance, supply chain management, and commerce, cybersecurity teams are urged to prioritize the immediate deployment of these updates.

Severe Vulnerabilities Threaten Core SAP Operations

Among the most pressing issues addressed this month is an improper authorization vulnerability in the Data Hub Adapter component of SAP Commerce Cloud. Identified as CVE-2026-58231, this flaw has been assigned a maximum CVSS score of 10.0. It specifically affects COM_CLOUD versions 2211 and 2211-JDK21. The highest severity rating indicates that exploiting this vulnerability requires no prior authentication or user interaction, potentially granting remote attackers full control over the confidentiality, integrity, and availability of affected systems.

Another critical vulnerability involves a code injection flaw within SAP Manufacturing Integration and Intelligence. Tracked as CVE-2026-44772, this issue holds a CVSS score of 9.9. Successful exploitation of this vulnerability, which impacts XMII and MII_ADMIN versions 15.4 and 15.5, could allow adversaries to execute arbitrary code within essential manufacturing software environments. A related code injection vulnerability in the same component, CVE-2026-44758, also rates as critical with a CVSS score of 9.1.

Memory Corruption Risks and Broader Impacts

Memory corruption vulnerabilities are also a significant concern in this patch cycle. CVE-2026-34265, with a CVSS score of 9.8, addresses a severe memory corruption flaw affecting the Application Server ABAP component within SAP NetWeaver and the ABAP Platform. This vulnerability impacts a broad spectrum of kernel versions, from 7.22 up to the more recent 9.19 releases.

Memory corruption flaws in foundational application servers are particularly dangerous because they can be weaponized by attackers to achieve remote code execution, providing initial access that can then be used to pivot and move laterally across corporate networks. Organizations must apply these critical SAP patches promptly to prevent threat actors from developing and deploying reliable exploit chains.

As detailed in the official SAP August 2026 Security Patch Day advisory, enterprise systems are under constant threat from sophisticated cyberattack groups. Applying these security updates is crucial to prevent adversaries from exploiting unpatched infrastructure or leveraging vulnerabilities like SQL injection against critical business databases.

SAP Note / Advisory CVE Vulnerability Affected Product CVSS
3771065 CVE-2026-58231 Improper authorization SAP Commerce Cloud (Data Hub Adapter), COM_CLOUD 2211 / 2211-JDK21 10.0
3765948 CVE-2026-44772 Code injection SAP Manufacturing Integration and Intelligence; XMII and MII_ADMIN 15.4 / 15.5 9.9
3714806 CVE-2026-34265 Memory corruption SAP NetWeaver and ABAP Platform; affected kernel versions 7.22–9.19 9.8
3758900 CVE-2026-44758 Code injection SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 9.1
3772411 CVE-2026-58243 Privilege escalation SAP ABAP Developer Tools; SAP_BASIS 750–758, 816, 918, 920 8.8
3773203 CVE-2026-42945 Potential buffer overflow SAP Commerce Cloud public-cloud deployments with NGINX 8.1
3756565 CVE-2026-66763 Credentials disclosure SAP BusinessObjects BI Platform (Central Management Server) 7.9
3727078 CVE-2026-58233 Remote code execution; updated July 2026 note SAP Change and Transport System Attach Tool (ctsattach), CTS_UPLOAD_CLT 1 7.6
3759854 CVE-2026-44763 Directory traversal SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 7.6
3758657 CVE-2026-44765 Missing authorization check SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 7.3
3758910 CVE-2026-44764 Missing authorization check SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 7.3
3786038 CVE-2026-58230 and 10 related CVEs Multiple vulnerabilities SAP Business AI Platform (Approuter), versions earlier than 23.0.0 7.0
3753141 CVE-2026-58248 XML external entity injection SAP BusinessObjects Business Intelligence 6.5
3770868 CVE-2026-34480 Improper output encoding in Apache Log4j Core SAP Commerce Cloud and SAP Data Hub 6.5
3757815 CVE-2026-5598 Potential information disclosure in Bouncy Castle Java library SAP Commerce Cloud 6.5
3721424 CVE-2026-66779 Cross-site scripting SAP NetWeaver Application Server ABAP 6.3
3766473 CVE-2026-66770 SQL injection SAP Social Intelligence; S4FND 102–109 6.3
3758318 CVE-2026-58235 Vulnerable third-party component SAP NetWeaver AS Java (Adobe Document Services) 6.3
3772071 CVE-2026-66771 Cross-site scripting SAPUI5 6.1
GHSA-hc5j-q32w-c25v CVE-2026-66773 Server-controlled __next URL lacks cross-origin validation pyodata Python package, versions earlier than 1.11.2 5.9
3745182 CVE-2026-58236 OS command injection SAP NetWeaver Application Server ABAP and ABAP Platform 5.5
3540688 CVE-2025-42947 Code injection; updated July 2025 note SAP FICA ODN Framework 5.5
3725940 CVE-2026-40130 Memory corruption SAPSPrint Service, SAPSPRINT 8.00 / 8.10 5.3
3756674 CVE-2026-58247 Memory corruption SAP ABAP Platform; selected kernel 7.53–7.77 versions 5.3
3778462 CVE-2026-33871, CVE-2025-58057 Multiple vulnerabilities SAP Commerce Cloud Search and Navigation 4.8
3669608 CVE-2026-66764 Missing authorization check SAP S/4HANA Reprocess Bank Statement Items 4.3
3770649 CVE-2026-66772 Missing authorization check SAP BusinessObjects BI Platform Admin Tools; also listed for S/4HANA 4.3
3781137 CVE-2026-58244 Missing authorization check SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 4.3
3752864 CVE-2026-58241 Missing authorization check SAP NetWeaver and ABAP Platform Change and Transport System wizard 4.2
3763028 CVE-2026-58245 Hard-coded credentials SAP Advanced Planning and Optimization Model Mix Planning 3.8
3739913 CVE-2026-44762 Security misconfiguration SAP Data Services Management Console 3.7

Beyond the critical-rated bugs, several high-severity issues also necessitate immediate attention:

  • Privilege Escalation (CVE-2026-58243): This vulnerability, scoring 8.8, affects a wide array of SAP_BASIS versions within SAP ABAP Developer Tools.
  • Public-Cloud Buffer Overflow (CVE-2026-42945): With a CVSS score of 8.1, this flaw impacts SAP Commerce Cloud environments that utilize NGINX in public-cloud configurations.
  • CTS Attach Tool RCE (CVE-2026-58233): SAP has provided updated guidance for a remote code execution vulnerability in the Change and Transport System Attach Tool (ctsattach), which was initially disclosed in July 2026.
  • Additional High-Severity Notes: These include vulnerabilities leading to credential disclosure in the SAP BusinessObjects Business Intelligence Platform, as well as directory traversal and missing authorization checks in Manufacturing Integration and Intelligence.

The remaining medium and low-severity notes address a diverse range of flaws across various SAP modules. These encompass cross-site scripting (XSS) vulnerabilities in SAPUI5 and NetWeaver Application Server ABAP, SQL injection in SAP Social Intelligence, XML External Entity (XXE) injection in BusinessObjects, a vulnerability in the pyodata Python library (GHSA-hc5j-q32w-c25v), and an information disclosure issue in the Bouncy Castle Java library used by Commerce Cloud.

Considering the extensive range of affected products, including NetWeaver, ABAP Platform, Commerce Cloud, BusinessObjects, and Manufacturing Integration and Intelligence, security administrators must prioritize applying these SAP security updates without delay.

What You Should Do

  • Identify Exposed Instances: Conduct a comprehensive inventory of all public-facing and internal SAP deployments running Commerce Cloud, NetWeaver, or Manufacturing Integration and Intelligence.
  • Prioritize Critical Notes: Immediately apply patches for CVE-2026-58231, CVE-2026-44772, and CVE-2026-34265, treating this as an emergency maintenance task.
  • Audit Developer Tools: Ensure all SAP_BASIS modules are updated to mitigate privilege escalation risks in developer environments.
  • Verify Third-Party Libraries: Confirm that underlying dependencies, such as the pyodata Python package and the Bouncy Castle Java library, are updated across all custom application extensions.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical Ivanti Endpoint Manager CVEs Let Remote Attackers Crash Agent Service

Next Post

LLM API Vulnerability Exposes AI Model Reasoning, Poses Data Risk

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Critical Vulnerability in Emerson Controllers Lets Attackers Spoof Temperatures
August 11, 2026
US SOCs Combat Alert Fatigue: Strategies for Cybersecurity Noise Reduction
August 11, 2026
Critical Windows PnP Vulnerability Lets Attackers Gain SYSTEM Access
August 11, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us