Multiple Vulnerabilities in SAP Products
18 August 2026
Attackers can exploit multiple vulnerabilities in SAP products to execute arbitrary code, disclose sensitive information or crash affected systems. Patch immediately.
Background
SAP has released security updates as part of its August 2026 SAP Security Patch Day, addressing multiple vulnerabilities in various SAP products. Notably, four critical-severity vulnerabilities (CVE-2026-58231, CVE-2026-44772, CVE-2026-34265 and CVE-2026-44758) and one high-severity vulnerability (CVE-2026-42945) have been identified. These vulnerabilities have Common Vulnerability Scoring System (CVSS) scores of 10.0, 9.9, 9.8, 9.1 and 8.1 out of 10, respectively.
Impact
Successful exploitation of these vulnerabilities could lead to the following:
CVE-2026-58231: An improper authorisation vulnerability in SAP Commerce Cloud could allow an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to functions lacking sufficient validation, leading to arbitrary code execution.
CVE-2026-44772: A code injection vulnerability in SAP Manufacturing Integration and Intelligence (MII) could enable low-privileged attackers to achieve arbitrary command execution by submitting specially crafted inputs, causing the application to fetch and process attacker-controlled content from an external source.
CVE-2026-34265: A memory corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform could allow an unauthenticated attacker to exploit logical errors in DIAG protocol parsing. Successful exploitation could disclose sensitive system information or crash the system.
CVE-2026-44758: A code injection vulnerability in SAP MII could allow an attacker with high privileges to submit specially crafted inputs to affected functionality lacking sufficient validation, leading to arbitrary command execution on the underlying operating system.
CVE-2026-42945: A vulnerability in the NGINX component within SAP Commerce Cloud public cloud deployments could cause a heap buffer overflow in the NGINX worker process. This may result in the worker process restarting and code execution on systems where the Address Space Layout Randomization is disabled or bypassed.
Known Exploitation
Exploitation attempts targeting CVE-2026-58231 have been observed in the wild.
Affected Products
These vulnerabilities affect the following products:
CVE-2026-58231
SAP Commerce Cloud (Data Hub Adapter) versions COM_CLOUD 2211, 2211-JDK21
CVE-2026-44772
SAP MII versions XMII 15.4, 15.5 and MII_ADMIN 15.4, 15.5
CVE-2026-34265
SAP NetWeaver and ABAP Platform versions KRNL64NUC 7.22, 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19; KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19
CVE-2026-44758
SAP MII versions XMII 15.4, 15.5
CVE-2026-42945
SAP Commerce Cloud versions COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211, 2211-JDK21
Recommendations
Users and administrators of affected products are advised to apply the relevant SAP security patches immediately.
References
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html?isu_page=1
https://nvd.nist.gov/vuln/detail/CVE-2026-58231
https://mallory.ai/vulnerabilities/CVE-2026-44772
https://nvd.nist.gov/vuln/detail/CVE-2026-34265
https://nvd.nist.gov/vuln/detail/CVE-2026-44758
https://nvd.nist.gov/vuln/detail/CVE-2026-42945
https://thehackernews.com/2026/08/sap-commerce-cloud-flaw-could-let.html
https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
