SAP Patches Critical Vulnerabilities Allowing Code Injection and Memory Corruption

On August 11, 2026, SAP released its latest Security Patch Day updates, addressing 28 new security notes and one GitHub security advisory, along with updates to two previously released notes. This comprehensive patch cycle targets several critical vulnerabilities that could enable unauthenticated attackers to inject malicious code, corrupt system memory, and escalate privileges across widely used enterprise platforms.

Critical Vulnerabilities in SAP Systems

Among the most severe issues resolved is an improper authorization vulnerability in SAP Commerce Cloud’s Data Hub Adapter, identified as CVE-2026-58231. This flaw, affecting versions 2211 and 2211-JDK21, carries a maximum CVSS score of 10.0. Exploitation requires no prior privileges or user interaction, potentially granting remote attackers full control over system confidentiality, integrity, and availability.

Another significant vulnerability is a code injection flaw in SAP Manufacturing Integration and Intelligence, designated as CVE-2026-44772 with a CVSS score of 9.9. Impacting versions 15.4 and 15.5, successful exploitation could allow adversaries to execute arbitrary code within critical manufacturing software. A related code injection issue, CVE-2026-44758 (CVSS 9.1), also affects the same component.

Additionally, a severe memory corruption vulnerability, CVE-2026-34265, with a CVSS score of 9.8, impacts the Application Server ABAP component within SAP NetWeaver and the ABAP Platform. This flaw spans kernel versions from 7.22 up to 9.19. Memory corruption vulnerabilities are particularly dangerous as they can be exploited to achieve remote code execution, providing initial access for lateral movement within corporate networks.

Additional Vulnerabilities Addressed

The patch release also addresses several other high-severity vulnerabilities:

  • CVE-2026-58243: A privilege escalation vulnerability in SAP ABAP Developer Tools, affecting SAP_BASIS versions 750–758, 816, 918, and 920, with a CVSS score of 8.8.
  • CVE-2026-42945: A potential buffer overflow in SAP Commerce Cloud public-cloud deployments with NGINX, carrying a CVSS score of 8.1.
  • CVE-2026-66763: A credentials disclosure issue in SAP BusinessObjects BI Platform’s Central Management Server, with a CVSS score of 7.9.

These vulnerabilities, if exploited, could lead to unauthorized access, data breaches, and significant operational disruptions.

Given the critical nature of these vulnerabilities and the extensive reliance on SAP systems for enterprise resource planning, finance, supply chain, and commerce operations, organizations are strongly advised to prioritize the application of these patches. Delaying remediation increases the risk of exploitation by threat actors, potentially leading to severe consequences for business operations and data security.