Enterprise software giant SAP has released a series of security updates addressing multiple critical vulnerabilities. These updates, announced on Tuesday, include 28 new security notes, two updates to existing notes, and an advisory on GitHub. These actions are part of SAP’s ongoing effort to enhance the security of its software offerings.
Critical Vulnerabilities Resolved
The August 2026 Security Patch Day saw SAP tackle several high-risk issues, including CVE-2026-58231, which received a perfect CVSS score of 10/10. This vulnerability in SAP Commerce Cloud’s Data Hub Adapter could allow unauthorized access through improper authorization, potentially leading to code execution and compromising the system’s confidentiality, integrity, and availability.
Additionally, SAP addressed two major code injection vulnerabilities within its Manufacturing Integration and Intelligence platform. These vulnerabilities, identified as CVE-2026-44772 and CVE-2026-44758, have been assigned CVSS scores of 9.9/10 and 9.1/10, respectively. These flaws could enable attackers to execute arbitrary commands, severely compromising the infrastructure.
Memory Corruption and Additional Risks
The fourth critical flaw, CVE-2026-34265, involves a memory corruption issue within the Application Server ABAP for NetWeaver and ABAP Platform. Rated at 9.8/10 on the CVSS scale, this vulnerability stems from logical errors in DIAG protocol parsing. It poses a threat to sensitive information security and system stability, as it can be exploited without authentication.
Prior to this patch release, SAP had updated a critical security note from July 2026, addressing a memory corruption issue in the NetWeaver Application Server ABAP. This update provided additional details and resolutions for the defect.
Focus on High-Severity Flaws
In addition to the critical patches, SAP released eight notes targeting high-severity vulnerabilities across various platforms, including ABAP Developer Tools, Commerce Cloud, and the Change and Transport System Attach Tool. Issues such as privilege escalation, buffer overflow, remote code execution, and credentials disclosure were addressed, further bolstering the security framework.
The seventh note specifically resolves 11 security issues within the Business AI Platform’s Approuter, highlighting SAP’s commitment to securing its enterprise solutions. Further notes were released for medium- and low-severity vulnerabilities, ensuring comprehensive coverage.
These security measures are crucial for maintaining the integrity of SAP’s software, though there is no current evidence of these vulnerabilities being exploited in the wild.
With these updates, SAP continues to prioritize cybersecurity, reinforcing its software against potential threats and enhancing user trust.
