For its August Patch Day, SAP has released 28 new security notes and updated two previously published advisories. One of the vulnerabilities received the maximum possible CVSS score of 10.0.
The most severe issue affects the Data Hub Adapter in SAP Commerce Cloud and is tracked as CVE-2026-58231. The vulnerability is caused by an authorization check flaw. Successful exploitation allows attackers to bypass authentication without logging in first. According to SAP’s patch notes, the vulnerability may also allow code execution and access to internal system components. This puts the confidentiality, integrity, and availability of the application at risk.
MII: Two Paths to Code Execution
SAP is also addressing two additional critical vulnerabilities in Manufacturing Integration and Intelligence (MII). Both are caused by improper input validation in specific servlets. CVE-2026-44772 has a CVSS score of 9.9, while CVE-2026-44758 is rated 9.1.
In both cases, attackers can craft malicious input that ultimately causes arbitrary commands to be executed on the server. Under the worst-case scenario, this could result in a complete compromise of the underlying infrastructure. According to SAP security specialist Onapsis, the key difference between the two vulnerabilities is the level of access required: only one of them requires attackers to already have elevated privileges.
Memory Flaw Exploitable Without Login
The fourth critical vulnerability affects the Application Server ABAP for NetWeaver and the ABAP Platform. Listed as CVE-2026-34265 and rated 9.8, the flaw is caused by logic errors in the processing of the DIAG protocol. Unlike the previously mentioned vulnerabilities, this issue can be exploited without any authentication. Potential consequences include the theft of sensitive data or causing the system to crash.
Update to a Previous Advisory
Alongside the new vulnerabilities, SAP has also revised a security note originally published in July. At the time, the company had already fixed a critical memory corruption vulnerability in the NetWeaver Application Server ABAP. The latest version of the advisory now provides additional information about the issue.
Eight High-Severity Vulnerabilities
Eight additional vulnerabilities are rated high in severity. They affect the ABAP Developer Tools, Commerce Cloud, Change and Transport System Attach Tool, BusinessObjects, MII, and the Business AI Platform, specifically its Approuter component. The reported issues include privilege escalation, buffer overflows, remote code execution, credential exposure, directory traversal, and missing authorization checks. The Approuter advisory alone covers 11 individual vulnerabilities.
The remaining vulnerabilities addressed in the August Patch Day are rated medium or low risk. SAP says it is currently unaware of any of the vulnerabilities being actively exploited in the wild.
(Editorial Team)