Critical SAP Security Update Released in August 2026

Published:
Illustrative image about Critical SAP Security Update Released in August 2026

On August 12, 2026, SAP released a security update addressing 29 vulnerabilities across multiple products. The information was disseminated by INCIBE-CERT, identifying four vulnerabilities with critical severity. This SAP security update is relevant for SAP users and system administrators.

Affected Products by the SAP Security Update

The vulnerabilities affect a wide range of SAP products, including SAP Commerce Cloud (Data Hub Adapter), SAP Manufacturing Integration and Intelligence, SAP NetWeaver and ABAP Platform, SAP BusinessObjects Business Intelligence Platform, SAP Business AI Platform, SAPUI5, and SAP S/4 HANA, among others. The compromised versions include SAP NetWeaver from 7.22 to 9.19, and SAP Commerce Cloud COM_CLOUD 2211, along with numerous specific versions detailed by SAP.

Description of Critical Vulnerabilities

Additional image about Critical SAP Security Update Released in August 2026
  • CVE-2026-58231: Affects SAP Commerce Cloud. An unauthenticated attacker could exploit a default authentication client and send specially crafted data to functions without sufficient validation. This could allow arbitrary code execution and compromise internal components, affecting the confidentiality, integrity, and availability of the application.
  • CVE-2026-44772: Fixes a vulnerability in a servlet that allows a low-privileged attacker to send inputs designed to make the application retrieve and process attacker-controlled content from an external source. Exploiting this could allow arbitrary command execution on the underlying host and compromise resources beyond the affected component.
  • CVE-2026-34265: In the ABAP application server of SAP NetWeaver, an unauthenticated attacker can exploit errors in the DIAG protocol parsing, causing memory corruption. This could reveal sensitive system information or cause it to crash, affecting confidentiality, integrity, and availability.
  • CVE-2026-44758: In SAP Manufacturing Integration and Intelligence (MII), a high-privileged attacker can send specially crafted data to affected functionalities that do not perform sufficient validation. Exploitation would allow arbitrary command execution on the operating system, affecting the confidentiality, integrity, and availability of the application.

Recommendations for Applying the SAP Security Update

SAP recommends that customers visit their support portal and apply the available patches to protect their environments. The SAP security update released in August 2026 should be prioritized for implementation to address the identified vulnerabilities.

Context and Source of Information

The notice was published by INCIBE-CERT based on the official SAP reports corresponding to the August 2026 Security Patch Day. The original source includes the complete list of vulnerabilities, the assigned CVE codes, and the affected versions.

The official document can be consulted in the INCIBE-CERT bulletin.

Reviewed by
Published: 18/08/2026. Content reviewed using experience, authority and trustworthiness criteria (E-E-A-T).
Responsible use of AI
This article may have used artificial intelligence tools to support structure, editing, translation or review. Editorial responsibility and final review remain with Toni Berraquero. View AI policy
Photo of Toni
Article author
Toni Berraquero

Toni Berraquero has trained since the age of 12 and has experience in retail, private security, ecommerce, digital marketing, marketplaces, automation and business tools.

View Toni’s profile

☕ If this genuinely helped…

You can support the project or share this article in one click. At least this block does something useful.