SAP Patches Four Critical Flaws on August 2026 Patch Day, Including a Perfect-10 Severity Bug
A maximum-severity authentication bypass in SAP Commerce Cloud leads a batch of 28 new security fixes. Organisations running SAP software should patch now.

Key points
- SAP released 28 new security notes on its August 2026 Patch Day, four of which fix critical flaws.
- CVE-2026-58231, rated 10 out of 10 for severity, lets attackers break into SAP Commerce Cloud without a password.
- Two code-injection bugs in SAP Manufacturing Integration and Intelligence (CVE-2026-44772 and CVE-2026-44758) score 9.9 and 9.1 respectively.
- A fourth critical bug (CVE-2026-34265, CVSS 9.8) can crash SAP NetWeaver or leak sensitive data without any login required.
- SAP says none of the flaws are currently being exploited in the wild.
SAP, the German company whose business software runs payroll, inventory, and finance for thousands of large organisations worldwide, pushed out fixes for 28 newly discovered security weaknesses on Tuesday. Four of those fixes cover "critical" vulnerabilities, meaning flaws serious enough that attackers could take over affected systems or steal sensitive data.
What is the worst flaw?
The most dangerous bug is CVE-2026-58231, which carries a CVSS score (a standardised 0-to-10 scale for measuring how bad a security flaw is) of exactly 10 out of 10. A score that high is rare. It lives in SAP Commerce Cloud's Data Hub Adapter, a component that helps online shops share data with other systems.
The flaw is an "improper authorisation" issue, meaning the software fails to check whether someone is allowed to do what they are asking. An attacker anywhere on the internet could use it to skip the login screen entirely, run their own code on the server, and reach internal systems that should be off-limits. SAP has not published the specific patched version string in the advisory text, but the fix is included in Tuesday's release.
A second serious group of vulnerabilities sits in SAP Manufacturing Integration and Intelligence, software that connects factory-floor machines to enterprise systems. CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1) are both "code injection" flaws, where an attacker can feed the software specially crafted input that tricks it into running the attacker's own commands on the underlying server. Application security firm Onapsis notes that one of the two requires a higher level of existing access to exploit, which is the only thing separating a 9.9 from a 10.
The fourth critical patch covers CVE-2026-34265 (CVSS 9.8), a "memory corruption" bug in SAP NetWeaver's ABAP application server. Memory corruption means the software mishandles the data it stores in memory, which attackers can exploit to crash the system or extract information it was never meant to reveal. No login is required to trigger this one.
Should IT teams at SAP customers act now?
Yes. SAP products are heavily targeted because a single compromised SAP system can expose an entire organisation's finances, HR records, and supply-chain data. None of these flaws are reported as actively exploited yet, as SecurityWeek first noted, but that window tends to close fast after a public disclosure.
| CVE | Affected Product | CVSS | Attack Requires Login? |
|---|---|---|---|
| CVE-2026-58231 | Commerce Cloud (Data Hub Adapter) | 10.0 | No |
| CVE-2026-44772 | Manufacturing Integration and Intelligence | 9.9 | No |
| CVE-2026-34265 | NetWeaver ABAP / ABAP Platform | 9.8 | No |
| CVE-2026-44758 | Manufacturing Integration and Intelligence | 9.1 | Partial |
Beyond the critical four, SAP released eight notes covering high-severity bugs across ABAP Developer Tools, BusinessObjects, and Business AI Platform, among others. The remaining notes address medium and low-severity issues.
If your organisation uses any SAP product, the practical step is straightforward: contact your SAP administrator today and confirm that August's patches are queued for immediate deployment.



