SAP Patches Critical Code Injection and Memory Corruption Vulnerabilities
SAP has released 28 new security notes, including four critical vulnerabilities related to code injection and memory corruption, with one flaw rated CVSS 10/10.

Enterprise software giant SAP has rolled out its August 2026 security patch day updates, addressing a total of 28 new security notes and updating two previous ones. Among these, four vulnerabilities have been classified as critical, highlighting significant risks for organizations utilizing SAP products. These patches are essential for maintaining the security posture of SAP environments against potential exploitation.
The most severe of the newly patched flaws is CVE-2026-58231, an improper authorization vulnerability within SAP Commerce Cloud (Data Hub Adapter). This critical defect, carrying a perfect CVSS score of 10/10, could allow unauthenticated remote attackers to bypass authentication mechanisms. Successful exploitation could lead to unauthorized access to internal components, compromising the confidentiality, integrity, and availability of sensitive data and system functions.
SAP also addressed two critical code injection vulnerabilities in its Manufacturing Integration and Intelligence (MII) component. Tracked as CVE-2026-44772 (CVSS 9.9/10) and CVE-2026-44758 (CVSS 9.1/10), these flaws reside in vulnerable servlets. Attackers can exploit these by submitting specially crafted input, enabling them to execute arbitrary commands on the underlying host system. This could result in a complete compromise of the affected infrastructure. While similar in nature, one of these vulnerabilities requires higher privileges for exploitation, according to analysis by application security firm Onapsis.
The fourth critical vulnerability patched this month is CVE-2026-34265, a memory corruption issue affecting the Application Server ABAP for NetWeaver and ABAP Platform. This flaw stems from logical errors in the DIAG protocol parsing. It can be exploited by unauthenticated attackers, potentially leading to the disclosure of sensitive information or system crashes, thereby impacting the confidentiality, integrity, and availability of applications running on these platforms.
In addition to the new critical issues, SAP also updated a critical security note from July 2026 concerning a memory corruption bug in NetWeaver Application Server ABAP. This update provides further details on the vulnerability and its resolution. The company also released eight notes addressing high-severity flaws across various products, including ABAP Developer Tools, Commerce Cloud, Change and Transport System Attach Tool, BusinessObjects, Manufacturing Integration and Intelligence, and Business AI Platform (Approuter). These high-severity issues encompass privilege escalation, buffer overflows, remote code execution (RCE), credential disclosure, directory traversal, and missing authorization checks.
The remaining security notes from SAP's August patch day address vulnerabilities of medium and low severity. Notably, SAP has not indicated any of these vulnerabilities are currently being exploited in the wild. However, the presence of multiple critical flaws, including those with CVSS scores of 10/10 and 9.9/10, underscores the importance of prompt patching for all organizations using SAP software to mitigate significant security risks.
These patches are part of SAP's regular security maintenance cycle, aiming to proactively address potential threats and vulnerabilities within its extensive product portfolio. Organizations are strongly advised to review the released security notes and prioritize the implementation of these updates to safeguard their critical business systems and data from potential cyberattacks.
This latest advisory from SAP details 28 new security notes released on August 11, 2026, expanding on the initial August patch day. Notably, it highlights CVE-2026-34265, a critical memory corruption vulnerability in SAP NetWeaver and ABAP Platform affecting a wide range of kernel versions, carrying a CVSS score of 9.8. Additionally, the advisory details two further code injection flaws in SAP Manufacturing Integration and Intelligence (CVE-2026-44772 and CVE-2026-44758) and a severe improper authorization flaw in SAP Commerce Cloud (CVE-2026-58231) with a CVSS 10.0 rating.