SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug
A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.

Key points
- SAP released 28 new security notes on its August 2026 Patch Day, four of which fix critical flaws.
- CVE-2026-58231, rated 10 out of 10 for severity, lets attackers break into SAP Commerce Cloud without a password.
- Two code-injection bugs in SAP Manufacturing Integration and Intelligence (CVE-2026-44772 and CVE-2026-44758) score 9.9 and 9.1 respectively.
- A fourth critical bug (CVE-2026-34265, CVSS 9.8) can crash SAP NetWeaver or leak sensitive data without any login required.
- SAP says none of the flaws are currently being exploited in the wild.
SAP, the German company whose business software runs payroll and finance for thousands of large organisations worldwide, pushed out fixes for 28 newly discovered security weaknesses on Tuesday. Four cover "critical" vulnerabilities, serious enough that attackers could take over affected systems or steal sensitive data.
What is the worst flaw?
The most dangerous bug is CVE-2026-58231, which carries a CVSS score (a standardised 0-to-10 scale measuring how bad a flaw is) of exactly 10. That's rare. It lives in SAP Commerce Cloud's Data Hub Adapter, a component that helps online shops share data with other systems.
The flaw is an "improper authorisation" issue: the software fails to check whether someone is allowed to do what they're asking. An attacker anywhere on the internet could skip the login screen entirely, run their own code on the server, and reach internal systems that should be off-limits.
A second group of vulnerabilities sits in SAP Manufacturing Integration and Intelligence, software that connects factory-floor machines to enterprise systems. CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1) are both code-injection flaws, where an attacker feeds the software specially crafted input that tricks it into running arbitrary commands on the underlying server. Onapsis notes that one of the two requires higher existing privileges to exploit, which is why it scores 9.9 rather than a perfect 10.
The fourth critical patch covers CVE-2026-34265 (CVSS 9.8), a memory-corruption bug rooted in logical errors in DIAG protocol parsing inside SAP NetWeaver's ABAP application server. Memory corruption means the software mishandles data stored in memory; attackers can exploit it to crash the system or extract information it was never meant to reveal. No login required.
Should IT teams at SAP customers act now?
Yes. A compromised SAP system can expose an entire organisation's finances and HR records in one move. None of these flaws are reported as actively exploited yet, as SecurityWeek first noted, but that window closes fast after public disclosure. We've seen exactly that pattern play out: our 20 July report on CVE-2026-6875 found attackers hitting ServiceNow within days of its patch shipping.
| CVE | Affected Product | CVSS | Attack Requires Login? |
|---|---|---|---|
| CVE-2026-58231 | Commerce Cloud (Data Hub Adapter) | 10.0 | No |
| CVE-2026-44772 | Manufacturing Integration and Intelligence | 9.9 | No |
| CVE-2026-34265 | NetWeaver ABAP / ABAP Platform | 9.8 | No |
| CVE-2026-44758 | Manufacturing Integration and Intelligence | 9.1 | Partial |
Beyond the critical four, SAP released eight notes covering high-severity bugs across ABAP Developer Tools, BusinessObjects, Commerce Cloud, and Manufacturing Integration and Intelligence, among others. The eighth note alone resolves 11 defects in the Business AI Platform's Approuter component. The remaining notes address medium and low-severity issues.
Contact your SAP administrator today and confirm that August's patches are queued for immediate deployment. The perfect-10 score on CVE-2026-58231 will draw attention from attackers quickly.



