SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new security notes, two updates, and a GitHub advisory in its August 2026 Security Patch Day, including several critical flaws across Commerce Cloud, Manufacturing Integration and Intelligence, and NetWeaver ABAP. The most severe issues could enable authentication bypass, remote code execution, memory corruption, and disclosure of sensitive data, though SAP says there is no sign of in-the-wild exploitation. #SAP #SAPCommerceCloud #NetWeaverABAP #ManufacturingIntegrationandIntelligence #APprouter

Keypoints

  • SAP published 28 new security notes, two updates, and a GitHub advisory.
  • CVE-2026-58231 is a critical authorization flaw in SAP Commerce Cloud that may allow authentication bypass and code execution.
  • CVE-2026-44772 and CVE-2026-44758 are critical code injection bugs in Manufacturing Integration and Intelligence.
  • CVE-2026-34265 affects NetWeaver Application Server ABAP and can expose data or crash systems through DIAG parsing flaws.
  • Other fixes address high-severity issues in ABAP Developer Tools, BusinessObjects, Business AI Platform, and Approuter.

Read More: https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/