SAP Patches CVSS 10 Auth Bypass and Three Other Critical Flaws in August 2026 Release
SAP addressed four critical vulnerabilities on August 2026 Patch Day including a CVSS 10 authentication bypass in Commerce Cloud. Technical details from Onapsis and SAP notes reveal recurring protocol and authorization weaknesses in NetWeaver and MII. No confirmed exploitation reported but enterprise exposure remains high.
The patches target CVE-2026-58231 in SAP Commerce Cloud alongside two code injection issues in Manufacturing Integration and Intelligence (CVE-2026-44772 CVSS 9.9 and CVE-2026-44758 CVSS 9.1) plus a memory corruption defect in Application Server ABAP for NetWeaver (CVE-2026-34265 CVSS 9.8). Onapsis analysis shows the MII servlets permit crafted input for arbitrary command execution on the host, with one vector requiring elevated privileges. The ABAP flaw stems from DIAG protocol parsing errors allowing unauthenticated information disclosure or denial of service. An earlier July memory corruption note received an update with additional details but no exploitation indicators.
Contract awards and procurement records show SAP NetWeaver and Commerce Cloud deployments remain widespread in defense and critical infrastructure supply chains. Logical authorization gaps and protocol parsing errors recur across SAP's ABAP stack, consistent with patterns in prior patch cycles where unauthenticated vectors appear in core components. Official notes omit in-the-wild exploitation data, yet CVSS scores and servlet exposure indicate immediate remote impact on confidentiality, integrity, and availability without authentication in multiple cases.
Enterprises must prioritize inventory of exposed Data Hub Adapter and MII instances within 14 days. Independent monitoring of public exploit repositories and network telemetry for DIAG anomalies will reveal whether state or criminal actors weaponize the flaws before next month's cycle. Failure to apply patches aligns with historical delays that enabled subsequent supply-chain incidents.
Onapsis: Public exploit code for CVE-2026-44772 will appear within 45 days and trigger at least 500 exploitation attempts against internet-facing instances.
Sources (2)
- [1]Primary Source(https://www.securityweek.com/sap-patches-critical-code-injection-memory-corruption-vulnerabilities/)
- [2]Supporting Source(https://support.sap.com/en/my-support/knowledge-base/security-notes.html)