CVE Tools

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SecurityWeekBy Ionut Arghire

PatchSAP Commerce CloudManufacturing Integration and Intelligence

Our summary

SAP has issued its August 2026 security patch day updates, addressing four critical vulnerabilities including CVE-2026-58231, a CVSS 10/10 authentication bypass flaw in SAP Commerce Cloud that allows remote code execution. Additionally, two critical code injection vulnerabilities, CVE-2026-44772 and CVE-2026-44758, affect Manufacturing Integration and Intelligence, enabling attackers to execute arbitrary commands via vulnerable servlets.

The final critical fix, CVE-2026-34265, addresses an unauthenticated memory corruption issue in Application Server ABAP for NetWeaver that can lead to system crashes or data disclosure. Administrators should apply the latest security notes to mitigate these risks, particularly given the high exploitability of the remote code execution vectors.

Read at SecurityWeek

SecurityWeek publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store