Critical SAP Vulnerabilities Let Attackers Inject Malicious Code and Corrupt Memory

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Spread the love

SAP’s August 2026 Security Patch Day has delivered a substantial round of fixes, addressing 28 new security notes and one GitHub security advisory, alongside two updates to previously released notes.

Released on August 11, 2026, this patch batch mitigates several critical-severity flaws that could allow unauthenticated attackers to inject malicious code, corrupt system memory, and escalate privileges across widely deployed enterprise platforms.

Given the extensive enterprise reliance on SAP systems for enterprise resource planning, finance, supply chain, and commerce operations, security teams are strongly advised to treat this update cycle as an emergency priority.

Critical SAP Vulnerabilities Enable Malicious Code Injection

The most alarming issue resolved this month is an improper authorization vulnerability in SAP Commerce Cloud’s Data Hub Adapter. Tracked as CVE-2026-58231, the flaw carries a maximum CVSS score of 10.0 and affects COM_CLOUD versions 2211 and 2211-JDK21.

Its maximum severity rating indicates that exploitation requires no prior privileges or user interaction, granting remote attackers complete control over confidentiality, integrity, and availability.

Following closely is a critical code injection vulnerability in SAP Manufacturing Integration and Intelligence, designated as CVE-2026-44772 with a CVSS score of 9.9.

Impacting XMII and MII_ADMIN versions 15.4 and 15.5, successful exploitation allows adversaries to execute arbitrary code within production-critical manufacturing software.

A second code injection bug in the same component, CVE-2026-44758 (CVSS 9.1), rounds out the critical tier.

Memory corruption risks also feature prominently in this release cycle. Tracked as CVE-2026-34265 with a CVSS score of 9.8, a severe memory corruption bug impacts the Application Server ABAP component within SAP NetWeaver and the ABAP Platform.

The vulnerability spans a wide range of kernel versions, from 7.22 up to the modern 9.19 releases.

Memory corruption flaws in core application servers are particularly dangerous because adversaries can weaponize them to achieve remote code execution, establishing initial access to pivot laterally across corporate networks.

Mitigating such systemic memory issues requires organizations to patch critical SAP vulnerabilities before threat actors build reliable exploit chains.

As outlined in the official SAP August 2026 Security Patch Day advisory, enterprise systems face continuous targeting from sophisticated threat groups. Applying these patches prevents adversaries from weaponizing unpatched infrastructure or leveraging SQL injection flaws against core business databases.

SAP Note / Advisory CVE Vulnerability Affected Product CVSS
3771065 CVE-2026-58231 Improper authorization SAP Commerce Cloud (Data Hub Adapter), COM_CLOUD 2211 / 2211-JDK21 10.0
3765948 CVE-2026-44772 Code injection SAP Manufacturing Integration and Intelligence; XMII and MII_ADMIN 15.4 / 15.5 9.9
3714806 CVE-2026-34265 Memory corruption SAP NetWeaver and ABAP Platform; affected kernel versions 7.22–9.19 9.8
3758900 CVE-2026-44758 Code injection SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 9.1
3772411 CVE-2026-58243 Privilege escalation SAP ABAP Developer Tools; SAP_BASIS 750–758, 816, 918, 920 8.8
3773203 CVE-2026-42945 Potential buffer overflow SAP Commerce Cloud public-cloud deployments with NGINX 8.1
3756565 CVE-2026-66763 Credentials disclosure SAP BusinessObjects BI Platform (Central Management Server) 7.9
3727078 CVE-2026-58233 Remote code execution; updated July 2026 note SAP Change and Transport System Attach Tool (ctsattach), CTS_UPLOAD_CLT 1 7.6
3759854 CVE-2026-44763 Directory traversal SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 7.6
3758657 CVE-2026-44765 Missing authorization check SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 7.3
3758910 CVE-2026-44764 Missing authorization check SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 7.3
3786038 CVE-2026-58230 and 10 related CVEs Multiple vulnerabilities SAP Business AI Platform (Approuter), versions earlier than 23.0.0 7.0
3753141 CVE-2026-58248 XML external entity injection SAP BusinessObjects Business Intelligence 6.5
3770868 CVE-2026-34480 Improper output encoding in Apache Log4j Core SAP Commerce Cloud and SAP Data Hub 6.5
3757815 CVE-2026-5598 Potential information disclosure in Bouncy Castle Java library SAP Commerce Cloud 6.5
3721424 CVE-2026-66779 Cross-site scripting SAP NetWeaver Application Server ABAP 6.3
3766473 CVE-2026-66770 SQL injection SAP Social Intelligence; S4FND 102–109 6.3
3758318 CVE-2026-58235 Vulnerable third-party component SAP NetWeaver AS Java (Adobe Document Services) 6.3
3772071 CVE-2026-66771 Cross-site scripting SAPUI5 6.1
GHSA-hc5j-q32w-c25v CVE-2026-66773 Server-controlled __next URL lacks cross-origin validation pyodata Python package, versions earlier than 1.11.2 5.9
3745182 CVE-2026-58236 OS command injection SAP NetWeaver Application Server ABAP and ABAP Platform 5.5
3540688 CVE-2025-42947 Code injection; updated July 2025 note SAP FICA ODN Framework 5.5
3725940 CVE-2026-40130 Memory corruption SAPSPrint Service, SAPSPRINT 8.00 / 8.10 5.3
3756674 CVE-2026-58247 Memory corruption SAP ABAP Platform; selected kernel 7.53–7.77 versions 5.3
3778462 CVE-2026-33871, CVE-2025-58057 Multiple vulnerabilities SAP Commerce Cloud Search and Navigation 4.8
3669608 CVE-2026-66764 Missing authorization check SAP S/4HANA Reprocess Bank Statement Items 4.3
3770649 CVE-2026-66772 Missing authorization check SAP BusinessObjects BI Platform Admin Tools; also listed for S/4HANA 4.3
3781137 CVE-2026-58244 Missing authorization check SAP Manufacturing Integration and Intelligence, XMII 15.4 / 15.5 4.3
3752864 CVE-2026-58241 Missing authorization check SAP NetWeaver and ABAP Platform Change and Transport System wizard 4.2
3763028 CVE-2026-58245 Hard-coded credentials SAP Advanced Planning and Optimization Model Mix Planning 3.8
3739913 CVE-2026-44762 Security misconfiguration SAP Data Services Management Console 3.7

Beyond the critical-rated bugs, several high-severity issues demand immediate remediation:

  • Privilege Escalation (CVE-2026-58243): Scores 8.8 and affects a broad range of SAP_BASIS versions inside SAP ABAP Developer Tools.
  • Public-Cloud Buffer Overflow (CVE-2026-42945): Scores 8.1 and impacts SAP Commerce Cloud environments running NGINX in public-cloud configurations.
  • CTS Attach Tool RCE (CVE-2026-58233): Updated guidance for a remote code execution flaw in the Change and Transport System Attach Tool (ctsattach), originally disclosed in July 2026.
  • Additional High-Severity Notes: Cover credential disclosure in the SAP BusinessObjects Business Intelligence Platform, as well as directory traversal and missing authorization checks in Manufacturing Integration and Intelligence.

The medium and low-severity notes address a broad spectrum of flaws across various modules.

These include cross-site scripting (XSS) in SAPUI5 and NetWeaver Application Server ABAP, SQL injection in SAP Social Intelligence, XML External Entity (XXE) injection in BusinessObjects, a vulnerable pyodata Python library flaw (GHSA-hc5j-q32w-c25v), and an information disclosure issue in the Bouncy Castle Java library utilized by Commerce Cloud.

Due to the wide footprint of impacted products including NetWeaver, ABAP Platform, Commerce Cloud, BusinessObjects, and Manufacturing Integration and Intelligence security administrators must prioritize applying these SAP security updates immediately.

  1. Identify Exposed Instances: Inventory all public-facing and internal SAP deployments running Commerce Cloud, NetWeaver, or MII.
  2. Prioritize Critical Notes: Apply patches for CVE-2026-58231, CVE-2026-44772, and CVE-2026-34265 on an emergency maintenance schedule.
  3. Audit Developer Tools: Update SAP_BASIS modules to resolve privilege escalation risks in developer environments.
  4. Verify Third-Party Libraries: Ensure underlying dependencies like pyodata and Bouncy Castle are updated across custom app extensions.

[Live Webinar] Join Elastic & UnderDefense to learn how small security teams can unify AI visibility and agentic response into one operating model -> Register Now