SAP Security Patch Day - August 2026

This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.

On 11th of August 2026, SAP security patch day saw the release of 28 new security notes and 1 Github security advisory. There are 2 updates to previously released security notes.

Note#

Title

Priority

CVSS

3771065

[CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

Product - SAP Commerce Cloud (Data Hub Adapter)
Version(s) - COM_CLOUD 2211, 2211-JDK21

Critical

10.0

3765948

[CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence

Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5, MII_ADMIN 15.4, 15.5

Critical

9.9

3714806

[CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform

Product - SAP NetWeaver and ABAP Platform
Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19

Critical

9.8

3758900

[CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence

Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5

Critical

9.1

3772411

[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools

Product - SAP ABAP Developer Tools
Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920

High

8.8

3773203

[CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX

Product - SAP Commerce Cloud
Version(s) - COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211, 2211-JDK21

High

8.1

3727078

Update to Security Note released on July 2026 Patch Day:

[CVE-2026-58233] Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach)

Product - SAP Change and Transport System Attach Tool (ctsattach)
Version(s) - CTS_UPLOAD_CLT 1

High

7.6

3756565

[CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)

Product - SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920, ENTERPRISE 430, 2025, 2027

High

7.9

3759854

[CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence

Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5

High

7.6

3758657

[CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5

High

7.3

3758910

[CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence

Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5

High

7.3

3786038

[CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)

Additional CVEs - CVE-2026-66775, CVE-2026-66778, CVE-2026-66760, CVE-2026-66761, CVE-2026-66777, CVE-2026-66776, CVE-2026-66774, CVE-2026-58237, CVE-2026-58238, CVE-2026-58239

Product - SAP Business AI Platform (Approuter)
Version(s) <23.0.0

High

7.0

3753141

[CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence

Product - SAP BusinessObjects Business Intelligence
Version(s) - ENTERPRISE 430, 2025, 2027, ENTERPRISECLIENTTOOLS 430, 2025, 2027

Medium

6.5

3770868

[CVE-2026-34480] Improper Output Encoding Vulnerability in SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core)

Product - SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core)
Version(s) - COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211

Medium

6.5

3757815

[CVE-2026-5598] Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library)

Product - SAP Commerce Cloud (Bouncy Castle Java library)
Version(s) - COM_CLOUD 2211, 2211-JDK21

Medium

6.5

3721424

[CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP

Product - SAP NetWeaver Application Server ABAP
Version(s) - SAP_UI 754, 755, 756, 757, 758, 816, EP-FLP 7.50, SAP_BASIS 731, AJAX-RUNTIME 7.50

Medium

6.3

3766473

[CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence

Product - SAP Social Intelligence
Version(s) - S4FND 102, 103, 104, 105, 106, 107, 108, 109

Medium

6.3

3758318

[CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)

Product - SAP NetWeaver AS Java (Adobe Document Services)
Version(s) - ADSSAP 7.50

Medium

6.3

3772071

[CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5

Product - SAPUI5
Version(s) - SAP_UI 750, 754, 755, 756, 757, 758, 816, UI_700 200

Medium

6.1

GHSA-hc5j-q32w-c25v

[CVE-2026-66773] Server-controlled `__next` URL is not checking cross-origin

Library – pyodata (pip)
Version(s) < 1.11.2

Medium

5.9

3745182

[CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform

Product - SAP NetWeaver Application Server ABAP and ABAP Platform
Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 9.16

Medium

5.5

3540688

Update to Security Note released on July 2025 Patch Day:

[CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework

Product – SAP FICA ODN framework
Versions – SAPSCORE 132, S4CORE 102, 103, 104, 105, 106, 107, 108, FI-CA 606, 616, 617, 618

Medium

5.5

3725940

[CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service

Product - SAPSPrint Service
Version(s) – SAPSPRINT 8.00, 8.10

Medium

5.3

3756674

[CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform

Product - SAP ABAP Platform
Version(s) - KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77

Medium

5.3

3778462

[Multiple CVEs] Security Vulnerabilities in SAP Commerce Cloud (Search and Navigation)

Related CVEs - CVE-2026-33871, CVE-2025-58057

Product - SAP Commerce Cloud (Search and Navigation)
Version(s) - COM_CLOUD 2211, 2211-JDK21

Medium

4.8

3669608

[CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)

Product - SAP S/4 HANA (Reprocess Bank Statement Items)
Version(s) - S4CORE 104, 105, 106, 107, 108, 109

Medium

4.3

3770649

[CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)

Product - SAP S/4 HANA (Reprocess Bank Statement Items), SAP BusinessObjects Business Intelligence Platform (Admin Tools)
Version(s) - S4CORE 104, 105, 106, 107, 108, 109, ENTERPRISE 430, 2025

Medium

4.3

3781137

[CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)

Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5

Medium

4.3

3752864

[CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)

Product - SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard
Version(s) - SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816

Medium

4.2

3763028

[CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)

Product - SAP Advanced Planning and Optimization (Model Mix Planning)
Version(s) - SCMAPO 713, 714, S4CORE 102, 103, 104, S4COREOP 104, 105, 106, 107, 108, 109, SCM 700, 701, 702, 712

Low

3.8

3739913

[CVE-2026-44762] Security Misconfiguration in SAP Data Services Management Console

Product - SAP Data Services Management Console
Version(s) - SBOP_DS_MANAGEMENT_CONSOLE 4.3, 2025

Low

3.7

To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.