SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug

A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.

ThreatVectr Newsdesk· 3 min read
Close-up, editorial news-photography style, of a single illuminated server rack panel in a darkened data centre, with amber and red indicator lights casting a f
Share

Key points

  • SAP released 28 new security notes on its August 2026 Patch Day, four of which fix critical flaws.
  • CVE-2026-58231, rated 10 out of 10 for severity, lets attackers break into SAP Commerce Cloud without a password.
  • Two code-injection bugs in SAP Manufacturing Integration and Intelligence (CVE-2026-44772 and CVE-2026-44758) score 9.9 and 9.1 respectively.
  • A fourth critical bug (CVE-2026-34265, CVSS 9.8) can crash SAP NetWeaver or leak sensitive data without any login required.
  • SAP says none of the flaws are currently being exploited in the wild.

SAP, the German company whose business software runs payroll, inventory, and finance for thousands of large organisations worldwide, pushed out fixes for 28 newly discovered security weaknesses on Tuesday. Four of those fixes cover "critical" vulnerabilities, meaning flaws serious enough that attackers could take over affected systems or steal sensitive data.

What is the worst flaw?

The most dangerous bug is CVE-2026-58231, which carries a CVSS score (a standardised 0-to-10 scale for measuring how bad a security flaw is) of exactly 10 out of 10. A score that high is rare. It lives in SAP Commerce Cloud's Data Hub Adapter, a component that helps online shops share data with other systems.

The flaw is an "improper authorisation" issue, meaning the software fails to check whether someone is allowed to do what they are asking. An attacker anywhere on the internet could use it to skip the login screen entirely, run their own code on the server, and reach internal systems that should be off-limits. SAP has not published the specific patched version string in the advisory text, but the fix is included in Tuesday's release.

A second serious group of vulnerabilities sits in SAP Manufacturing Integration and Intelligence, software that connects factory-floor machines to enterprise systems. CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1) are both "code injection" flaws, where an attacker can feed the software specially crafted input that tricks it into running the attacker's own commands on the underlying server. Application security firm Onapsis notes that one of the two requires a higher level of existing access to exploit, which is the only thing separating a 9.9 from a 10.

The fourth critical patch covers CVE-2026-34265 (CVSS 9.8), a "memory corruption" bug in SAP NetWeaver's ABAP application server. Memory corruption means the software mishandles the data it stores in memory, which attackers can exploit to crash the system or extract information it was never meant to reveal. No login is required to trigger this one.

Should IT teams at SAP customers act now?

Yes. SAP products are heavily targeted because a single compromised SAP system can expose an entire organisation's finances, HR records, and supply-chain data. None of these flaws are reported as actively exploited yet, as SecurityWeek first noted, but that window tends to close fast after a public disclosure.

CVE Affected Product CVSS Attack Requires Login?
CVE-2026-58231 Commerce Cloud (Data Hub Adapter) 10.0 No
CVE-2026-44772 Manufacturing Integration and Intelligence 9.9 No
CVE-2026-34265 NetWeaver ABAP / ABAP Platform 9.8 No
CVE-2026-44758 Manufacturing Integration and Intelligence 9.1 Partial

Beyond the critical four, SAP released eight notes covering high-severity bugs across ABAP Developer Tools, BusinessObjects, and Business AI Platform, among others. The remaining notes address medium and low-severity issues.

If your organisation uses any SAP product, the practical step is straightforward: contact your SAP administrator today and confirm that August's patches are queued for immediate deployment.

© 2026 Threat Vectr