SAP Releases Patches for Critical Code Injection and Memory Corruption Flaws

0
3

Key Takeaways

  • SAP released 28 new security notes, two updates to prior notes, and a GitHub advisory on its August 2026 Patch Day.
  • Four of the notes address critical vulnerabilities (CVSS ≥ 9.1), the most severe being CVE‑2026-58231 (CVSS 10/10) in SAP Commerce Cloud.
  • The critical flaws enable authentication bypass, arbitrary command execution, and memory corruption, potentially compromising confidentiality, integrity, and availability.
  • SAP also patched high‑severity issues in ABAP Developer Tools, Commerce Cloud, Change and Transport System Attach Tool, BusinessObjects, Manufacturing Integration and Intelligence, and the Business AI Platform (Approuter).
  • The remaining notes cover medium‑ and low‑severity defects; SAP has no evidence these are being exploited in the wild.
  • Organizations should prioritize applying the August 2026 patches, review the updated July note, and monitor SAP’s security advisories for emerging threats.

Overview of SAP August 2026 Patch Day
On Tuesday, SAP issued its regular monthly security update, publishing 28 new security notes, two revisions to previously released notes, and a GitHub advisory. The release forms part of SAP’s August 2026 Security Patch Day and addresses a broad spectrum of vulnerabilities across its product portfolio. While the majority of the notes resolve moderate‑risk issues, four notes are classified as critical, warranting immediate attention from SAP administrators and security teams. The update also includes supplementary information for a critical note originally published in July 2026, reflecting SAP’s ongoing effort to refine remediation guidance.

Critical Vulnerability in SAP Commerce Cloud (CVE‑2026-58231)
The most severe flaw disclosed is CVE‑2026-58231, carrying a CVSS score of 10/10. It resides in the SAP Commerce Cloud Data Hub Adapter and stems from an improper authorization check. An unauthenticated remote attacker can craft a request that bypasses authentication mechanisms, potentially leading to arbitrary code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the Commerce Cloud application, making it a top priority for patching. SAP recommends applying the corresponding security note immediately and reviewing any exposed Data Hub Adapter endpoints for signs of tampering.

Critical Code Injection Flaws in Manufacturing Integration and Intelligence
SAP also addressed two critical code injection vulnerabilities in its Manufacturing Integration and Intelligence (MII) module: CVE‑2026-44772 (CVSS 9.9/10) and CVE‑2026-44758 (CVSS 9.1/10). Both defects involve vulnerable servlets that accept specially crafted input, enabling attackers to execute arbitrary commands on the underlying host. While the technical root cause is similar, CVE‑2026-44772 requires higher privileges for exploitation, according to analysis by application security firm Onapsis. If exploited, these flaws could lead to total infrastructure compromise, underscoring the urgency of applying the associated patches and restricting servlet access to trusted networks only.

Memory Corruption in Application Server ABAP (CVE‑2026-34265)
The fourth critical issue, CVE‑2026-34265 (CVSS 9.8/10), affects the Application Server ABAP for NetWeaver and ABAP Platform. It is classified as a memory corruption vulnerability arising from logical errors in the DIAG protocol parsing process. An attacker can exploit this flaw without authentication to either disclose sensitive information or crash the system, thereby impacting confidentiality, integrity, and availability. SAP’s note advises administrators to apply the patch promptly and to monitor ABAP server logs for abnormal DIAG protocol activity that could indicate exploitation attempts.

Update to July 2026 Critical Note
Prior to the August release, SAP issued an update to a critical security note originally published on the July 2026 Patch Day. The update addresses a critical memory corruption bug in the NetWeaver Application Server ABAP. Although the core remediation remains unchanged, the revised note includes additional technical details, clarification on affected components, and refined mitigation steps. SAP encourages customers who applied the July note to review the updated version to ensure they have incorporated all recommended actions and to verify that no residual exposure remains.

High‑Severity Flaws Across Multiple Products
Beyond the four critical notes, SAP released eight notes addressing high‑severity vulnerabilities (CVSS 7.0‑8.9) in several components:

  • ABAP Developer Tools – privilege escalation and buffer overflow issues.
  • Commerce Cloud – additional authorization and input validation defects.
  • Change and Transport System Attach Tool – remote code execution and credentials disclosure flaws.
  • BusinessObjects – directory traversal and missing authorization checks.
  • Manufacturing Integration and Intelligence – further injection and logic flaws.
  • Business AI Platform (Approuter) – a single note that resolves eleven distinct security defects, ranging from insecure deserialization to insufficient logging.
    These high‑severity issues, while not as immediately catastrophic as the critical flaws, still pose substantial risk and should be prioritized in patch management cycles.

Medium‑ and Low‑Severity Notes
The remainder of the August 2026 Patch Day consists of notes covering medium‑ and low‑severity vulnerabilities. SAP explicitly states that none of these flaws are known to be exploited in the wild at the time of release. Nonetheless, they address issues such as insufficient input validation, information disclosure, and configuration weaknesses that could be chained with other exploits. Applying these updates contributes to a defense‑in‑depth strategy and reduces the attack surface over time.

No Evidence of Exploitation in the Wild
SAP’s advisory notes that, despite the severity of several vulnerabilities, there is currently no public evidence indicating active exploitation of any of the disclosed flaws. This assessment is based on threat intelligence feeds, internal monitoring, and collaboration with security research partners. However, the absence of observed exploitation does not diminish the importance of timely patching, as attackers may develop exploits shortly after disclosure. Organizations should treat the notes as urgent and integrate them into their regular patching schedules.

Related Vendor Advisories and Recommendations
The SAP release coincides with other high‑profile security announcements, including Cisco’s warning about high‑severity ClamAV vulnerabilities, Metabase’s patch for a zero‑day flaw, CISA’s urging of immediate patching for an exploited Progress LoadMaster vulnerability, and disclosure of a critical one‑click vulnerability in Atlassian’s Rovo AI. These concurrent alerts highlight a heightened threat landscape and reinforce the need for vigilant vulnerability management. SAP customers are advised to:

  1. Apply all August 2026 security notes without delay, prioritizing the four critical vulnerabilities.
  2. Review the updated July note for the NetWeaver ABAP memory corruption bug and ensure the latest guidance is followed.
  3. Conduct post‑patch validation—verify that services restart correctly, review logs for anomalous activity, and run vulnerability scans to confirm remediation.
  4. Enforce network segmentation and restrict exposure of susceptible components (e.g., Data Hub Adapter servlets, MII servlets, ABAP DIAG interfaces) to trusted zones.
  5. Stay informed by subscribing to SAP’s Security Note notifications and monitoring relevant CVE feeds for emerging threats.

By following these steps, enterprises can mitigate the risks posed by the August 2026 SAP security updates and maintain a robust security posture amid an evolving threat environment.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here