SAP: 25 Vulnerabilities Disclosed, Critical Commerce Cloud Flaw Actively Exploited
SAP disclosed 25 vulnerabilities on August 11, 2026, including a critical SAP Commerce Cloud flaw (CVE-2026-58231) actively exploited in the wild.

Key findings
- 25 SAP vulnerabilities disclosed on August 11, 2026, spanning critical to low severity across multiple products.
- Critical CVE-2026-58231 in SAP Commerce Cloud allows unauthenticated arbitrary code execution and is actively exploited.
- Multiple SAP Approuter vulnerabilities disclosed, impacting request handling, authorization, and session integrity.
- High-severity flaws include hard-coded credentials in BusinessObjects (CVE-2026-66763) and unauthorized database operations in ABAP Development Tools (CVE-2026-58243).
- SAP released patches on August 11, 2026, urging immediate attention due to active exploitation of CVE-2026-58231.
On August 11, 2026, SAP released a significant batch of 25 security advisories addressing vulnerabilities across its product portfolio. This coordinated disclosure event, spanning a 10-hour window, highlights critical and medium-severity flaws impacting various SAP solutions, including SAP Commerce Cloud, SAP NetWeaver, SAP Approuter, and SAP BusinessObjects Business Intelligence Platform. The most severe vulnerability, CVE-2026-58231, a critical-severity flaw in SAP Commerce Cloud, allows unauthenticated attackers to achieve arbitrary code execution, posing a significant risk to enterprise data and operations.
Several vulnerabilities cluster around the SAP Approuter component, with multiple medium-severity issues related to insufficient sanitization of request headers, inadequate validation of incoming requests, inconsistent integrity verification of session-related headers, and lack of default cross-site request forgery protection. These flaws, including CVE-2026-66778, CVE-2026-66777, CVE-2026-66776, and CVE-2026-66775, could lead to unauthorized information access, bypass of authorization checks, session hijacking, and potential account binding to attacker-controlled identities. Additionally, CVE-2026-66760 in SAP Approuter involves insufficient validation of client certificates in callback flows, potentially allowing bypass of identity checks under specific conditions. Other Approuter vulnerabilities include CVE-2026-66761, which can lead to unbounded memory growth due to improper flow control, and CVE-2026-66774 and CVE-2026-58239, which relate to error handling and tenant context validation, respectively, with low impact on availability and confidentiality. CVE-2026-58238 describes an Approuter vulnerability where crafted input can cause a crash and restart, requiring specific runtime conditions. CVE-2026-58237 in SAP Approuter's WebSocket functionality allows low-privileged attackers to access restricted information and perform limited modifications.
Other notable vulnerabilities include a critical SQL Injection flaw in SAP Social Intelligence (CVE-2026-66770), allowing authenticated attackers to alter database structure. SAP BusinessObjects Business Intelligence Platform is affected by CVE-2026-66763, a high-severity vulnerability where hard-coded cryptographic keys can lead to the decryption of stored sensitive credentials by attackers with high privileges and local access. Another BusinessObjects vulnerability, CVE-2026-58248, allows low-privileged attackers to upload malicious spreadsheet files that expose sensitive data. SAP NetWeaver Application Server ABAP and ABAP Platform are impacted by CVE-2026-58236, a medium-severity flaw enabling high-privileged attackers to bypass security controls and execute OS-level commands. Additionally, CVE-2026-58243, a high-severity vulnerability in SAP ABAP Development Tools, allows low-privileged attackers to perform unauthorized database operations. CVE-2026-66779, a medium-severity XSS vulnerability in SAP NetWeaver Application Server ABAP, could allow authenticated attackers to inject malicious scripts via crafted links. CVE-2026-66771 in SAPUI5 allows key users to inject malicious scripts into persisted application changes, potentially leading to sensitive data access.
The critical CVE-2026-58231 in SAP Commerce Cloud has seen active exploitation attempts starting as early as August 14, 2026, just three days after its disclosure, according to reports from Defused Cyber and other threat intelligence organizations. This exploitation occurred despite the absence of a public proof-of-concept exploit, indicating sophisticated threat actors targeting the vulnerability. The vulnerability allows unauthenticated remote code execution and impacts confidentiality, integrity, and availability.
SAP's August 2026 Security Patch Day addresses these numerous vulnerabilities, with patches and security notes released on August 11, 2026. Users are strongly advised to review the specific security notes for each affected product and apply the necessary updates to mitigate risks. The breadth of affected products underscores the importance of a comprehensive patch management strategy for SAP environments. Organizations should prioritize addressing the critical and high-severity vulnerabilities, particularly CVE-2026-58231, CVE-2026-66763, and CVE-2026-58243, to protect against potential exploitation. The ongoing exploitation of CVE-2026-58231 highlights the immediate need for remediation.
The sheer volume and severity of vulnerabilities disclosed on this single patch day emphasize the persistent threat landscape facing SAP systems. While SAP has provided fixes, the active exploitation of CVE-2026-58231 serves as a stark reminder that timely patching is crucial. Security teams managing SAP environments should remain vigilant, monitor for further exploitation attempts, and ensure all relevant systems are updated to the latest secure versions. The coordinated disclosure of these flaws allows organizations to address them proactively, but the rapid exploitation of the most critical issue necessitates an urgent response.