-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Security Patch Day - August 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.
On 11th of August 2026, SAP security patch day saw the release of 28 new security notes and 1 Github security advisory. There are 2 updates to previously released security notes.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) Product - SAP Commerce Cloud (Data Hub Adapter) | Critical | ||
[CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Critical | ||
[CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform Product - SAP NetWeaver and ABAP Platform | Critical | ||
[CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Critical | ||
[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools Product - SAP ABAP Developer Tools | High | ||
[CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX Product - SAP Commerce Cloud | High | ||
Update to Security Note released on July 2026 Patch Day: [CVE-2026-58233] Remote Code Execution vulnerability in SAP Change and Transport System Attach Tool (ctsattach) | High | ||
[CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) Product - SAP BusinessObjects Business Intelligence Platform (Central Management Server) | High | ||
[CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | High | ||
[CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | High | ||
[CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | High | ||
[CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter) Product - SAP Business AI Platform (Approuter) | High | ||
[CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence Product - SAP BusinessObjects Business Intelligence | Medium | ||
[CVE-2026-34480] Improper Output Encoding Vulnerability in SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core) Product - SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core) | Medium | ||
[CVE-2026-5598] Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library) Product - SAP Commerce Cloud (Bouncy Castle Java library) | Medium | ||
[CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP Product - SAP NetWeaver Application Server ABAP | Medium | ||
[CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence Product - SAP Social Intelligence | Medium | ||
[CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) Product - SAP NetWeaver AS Java (Adobe Document Services) | Medium | ||
[CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5 Product - SAPUI5 | Medium | ||
[CVE-2026-66773] Server-controlled `__next` URL is not checking cross-origin Library – pyodata (pip) | Medium | ||
[CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform Product - SAP NetWeaver Application Server ABAP and ABAP Platform | Medium | ||
Update to Security Note released on July 2025 Patch Day: Product – SAP FICA ODN framework | Medium | ||
[CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service Product - SAPSPrint Service | Medium | ||
[CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform Product - SAP ABAP Platform | Medium | ||
[Multiple CVEs] Security Vulnerabilities in SAP Commerce Cloud (Search and Navigation) Product - SAP Commerce Cloud (Search and Navigation) | Medium | ||
[CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items) Product - SAP S/4 HANA (Reprocess Bank Statement Items) | Medium | ||
[CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools) Product - SAP S/4 HANA (Reprocess Bank Statement Items), SAP BusinessObjects Business Intelligence Platform (Admin Tools) | Medium | ||
[CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII) Product - SAP Manufacturing Integration and Intelligence | Medium | ||
[CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) Product - SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard | Medium | ||
[CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning) Product - SAP Advanced Planning and Optimization (Model Mix Planning) | Low | ||
[CVE-2026-44762] Security Misconfiguration in SAP Data Services Management Console Product - SAP Data Services Management Console | Low |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.