TL;DR
SAP released its August 2026 Patch Day on August 11, with 28 new security notes. The headline flaw, CVE-2026-58231, scores a maximum CVSS 10.0. Several critical code injection bugs also enable remote code execution across core SAP products.
- Product: SAP_SE (2 products)
- Vulnerabilities: 2 flaws (CVE-2026-58231, CVE-2026-34265)
- Highest severity: 10.0 (Critical · CVSSv3)
- Worst impact: Improper Authorization in
- Status: No confirmed exploitation yet
- Action: See vendor advisories
| CVE | CVSS (CVSSv3) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-58231 | 10 | CWE-94 | — | Not exploited |
| CVE-2026-34265 | 9.8 | CWE-787 | — | Not exploited |
Why the SAP August 2026 Patch Day Matters
SAP software runs finance, supply chain, and manufacturing for many large enterprises. A single critical flaw can expose that core. This month, four notes carry critical severity, and three of them reach code execution.
The top bug, CVE-2026-58231, is an improper authorization issue in SAP Commerce Cloud. With a perfect 10.0 score, it demands immediate attention.
How the Attacks Work
The most dangerous notes involve code injection. CVE-2026-44772 (CVSS 9.9) affects SAP Manufacturing Integration and Intelligence. A second injection flaw, CVE-2026-44758 (CVSS 9.1), hits the same product.
Meanwhile, CVE-2026-34265 (CVSS 9.8) is a memory corruption bug in the NetWeaver ABAP kernel. Such flaws can let an attacker run code or crash the system. SAP also updated a note for CVE-2026-58233, a remote code execution bug in the Change and Transport System Attach Tool.
Key Critical and High Flaws
| CVE | Product | Type | CVSS |
|---|---|---|---|
| CVE-2026-58231 | SAP Commerce Cloud (Data Hub Adapter) | Improper authorization | 10.0 |
| CVE-2026-44772 | SAP MII | Code injection | 9.9 |
| CVE-2026-34265 | SAP NetWeaver / ABAP Platform | Memory corruption | 9.8 |
| CVE-2026-44758 | SAP MII | Code injection | 9.1 |
| CVE-2026-58243 | SAP ABAP Developer Tools | Privilege escalation | 8.8 |
| CVE-2026-58233 | SAP CTS Attach Tool | Remote code execution | 7.6 |
Affected Versions
The critical flaws hit widely deployed releases. CVE-2026-58231 affects SAP Commerce Cloud COM_CLOUD 2211 and 2211-JDK21. The MII bugs affect XMII 15.4 and 15.5. The memory corruption flaw spans many NetWeaver kernel versions, from 7.22 through 9.19.
Patch and Mitigation Steps
Apply the relevant security notes without delay. SAP publishes the full list in its August 2026 Security Notes overview. Prioritize the CVSS 10.0 and code injection notes first.
No public proof-of-concept or in-the-wild exploitation has been confirmed for these flaws. Still, attackers watch SAP patches closely, so fast patching remains the safest path.
Support Our Threat Intelligence
If you find our CVE report and cybersecurity news helpful, consider supporting our work.