SAP Security Notes: August 2026 Patch Day

Share

Critical vulnerabilities in SAP Commerce Cloud, Application Server ABAP for SAP NetWeaver/ABAP Platform and SAP MII

Highlights of August SAP Security Notes analysis include:

  • August Summary Thirty-three new and updated SAP security patches released, including five HotNews Notes and nine High Priority Notes
  • SAP MII in Focus Six vulnerabilities fixed in collaboration with Onapsis Research Labs, including 2 HotNews and 3 High Priority Notes
  • Onapsis Research Labs Contribution Our team supported SAP in patching fourteen vulnerabilities covered by eleven SAP Security Notes and one SAP Correction Note, including two tagged as HotNews and three tagged as High Priority

SAP has published thirty-three new and updated SAP Security Notes in its August Patch Day, including five HotNews Notes and nine High Priority Notes. Eleven of the twenty-nine new Security Notes were published in contribution with the Onapsis Research Labs.

Table displaying and overview of the August SAP security notes organized by system affected and severity.

The HotNews Notes in Detail

SAP Security Note #3771065, tagged with a CVSS score of 10.0, patches a critical vulnerability in SAP Commerce Cloud (Data Hub Adapter) caused by insufficient authorization checks and input validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application. Customers must patch to the fixed Commerce Cloud release levels referenced in the note and re-build/re-deploy the updated SAP Commerce Cloud version. As a temporary workaround, customers can reduce their exposure by configuring an IP Filter Set in SAP Commerce Cloud to restrict access to the vulnerable endpoint.

The Onapsis Research Labs (ORL) supported SAP in patching two of the three new HotNews Notes, both addressing critical Code Injection vulnerabilities in SAP Manufacturing Integration and Intelligence(SAP MII).

SAP Security Note #3765948, tagged with a CVSS score of 9.9, patches a vulnerable servlet that allows a low-privileged attacker to submit specially crafted input that causes the application to retrieve and process attacker-controlled content from an external source. Successful exploitation could enable execution of arbitrary commands on the underlying host and impact resources beyond the vulnerable component, resulting in a total infrastructure compromise.

After implementing the patch, customers need to maintain the new system property ‘Secure Transformer’ with a list of allowed hosts for hosting XSL files. Only XSL files from these hosts can be consumed by the vulnerable servlet.

As similar vulnerability is patched with SAP Security Note #3758900, tagged with a CVSS score of 9.1. It patches a vulnerable servlet component in SAP MII that is vulnerable to Server-Side Template Injection(SSTI) and Server-Side Request Forgery(SSRF). Successful exploitation could enable execution of arbitrary commands. In opposite to SAP Security Note #3765948, an attacker will need higher privileges which explains the slightly lower CVSS score.The patch removes the vulnerable servlet component.

SAP Security Note #3747367, tagged with a CVSS score of 9.9, was initially released on SAP’s July Patch Day. SAP has updated the note with additional information in the ‘Validity’and ‘Solution’ sections.

SAP Security Note #3714806, tagged with a CVSS score of 9.8, patches a Memory Corruption vulnerability in SAP NetWeaver AS ABAP and ABAP Platform Platform. Logical errors in DIAG protocol parsing allow an unauthenticated attacker to generate memory corruptions. The vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application. 

The High Priority Notes in Detail

SAP Security Note #3772411, tagged with a CVSS score of 8.8, patches a Privilege Escalation vulnerability in SAP ABAP Developer Tools. The SQL Console in SAP ABAP Developer Tools supported the use of host expressions within SQL statements to dynamically supply values.  This enables a low-privileged attacker to execute unauthorized database operations allowing them to read and modify sensitive data, and disrupt access for legitimate users. Details about the vulnerability can be found in SAP Note #3776714.

SAP Security Note #3732471, tagged with a CVSS score of 8.2, was initially released on SAP’s May Patch Day and was now updated for the second time with additional correction instructions for all affected SCM versions. 

SAP Security Note #3773203, tagged with a CVSS score of 8.1, addresses a Buffer Overflow vulnerability in SAP Commerce Cloud in public‑cloud deployments with NGINX. The patch is present on all SAP Commerce Cloud in the Public Cloud systems and customers can consume the patch by building and deploying their SAP Commerce Cloud applications to their environments. Keeping the applications unpatched will allow an unauthenticated attacker to send specially crafted requests that could trigger memory corruption in an internal process. Successful exploitation could lead to arbitrary code execution, resulting in high impact on confidentiality integrity and availability.   

SAP Security Note #3756565, tagged with a CVSS score of 7.9, patches a Credentials Disclosure vulnerability in SAP BusinessObjects Business Intelligence Platform (Central Management Server). An attacker with high privileges and local access to the server could retrieve user objects that include sensitive credential information, encrypted by a hard-coded key. With  knowledge of this key the stored credentials can easily be decrypted. The decrypted authentication data can then be used to modify protected information, resulting in a high impact on confidentiality and integrity. 

SAP Security Note #3773304, tagged with a CVSS score of 7.6, was initially released on SAP’s July Patch Day. The note describes a Remote Code Execution vulnerability in the Enhanced Change and Transport System (CTS+) Attach Tool. The updated note clearly states that there is no unaffected version of the tool and references SAP Note #2473648, providing details about how to remove the tool successfully.

In addition to the two HotNews Notes that patch critical vulnerabilities in SAP MII, our ORL team supported SAP in patching another three High Priority vulnerabilities in this application.

SAP Security Note #3759854, tagged with a CVSS score of 7.6, patches a Path Traversal vulnerability in SAP MII that allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Under certain conditions that are outside the attacker’s control, this could be exploited to write files outside the intended directory, resulting in a high impact on confidentiality, integrity, and availability. 

SAP Security Notes #3758657 and #3758910, both tagged with a CVSS score of 7.3, patch Missing Authorization Check vulnerabilities in SAP MII.

SAP Security Notes #3758657 is required to prevent unauthenticated remote attackers from accessing scheduling-related application functions without proper authorization validation. Otherwise, they could retrieve, create, modify, or delete application-managed scheduling data, causing a low impact on confidentiality, integrity, and availability.

SAP Security Note #3758910 describes that an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations enabling the attacker to read, create, modify, or delete application-managed business data.

SAP Security Note #3786038, tagged with a CVSS score of 7.0, patches eleven vulnerabilities in SAP Approuter.     

Onapsis Contribution

The Onapsis Research Labs (ORL) contributed significantly to SAP’s August Patch Day. In addition to two HotNews Notes and three High Priority Notes, the ORL supported SAP in patching another 9 vulnerabilities covered by six Medium Priority Notes and one SAP Correction Note:

Our ORL team detected a functionality in SAP Social Intelligence that is vulnerable to SQL Injection. The vulnerability allows an authenticated attacker to directly inject an SQL DDL (Data Definition Language) string into the underlying database without further authorization. Successful exploitation could allow them to make malicious changes to the database structure, resulting in a low impact to the confidentiality, integrity, and availability of the system. SAP Security Note #3766473, tagged with a CVSS score of 6.3, patches the vulnerability by removing the vulnerable functionality from the application. 

SAP Security Note #3725940, tagged with a CVSS score of 5.3, patches three Memory Corruption vulnerabilities in SAPSPrint Service. Our team detected that the application did not properly validate incoming network data, allowing an unauthenticated attacker to send a specially crafted request that caused memory corruption and a service crash, resulting in denial of service. 

Another Memory Corruption vulnerability was identified by the ORL team in SAP ABAP Platform. SAP Security Note #3756674, tagged with a CVSS score of 5.3, explains that the vulnerability allows an unauthenticated user to send a specially crafted request to an internal component which could disclose limited, non-sensitive data from previously used memory, leading to a low on confidentiality, with no impact on integrity and availability of the application.

SAP Security Note #3781137, tagged with a CVSS score of 4.3, is another vulnerability in SAP MII that was patched in collaboration with the ORL team on SAP’s August Patch Day. Missing authorization checks on certain application functions allow a low-privileged authenticated attacker to access information that should be restricted to privileged users. 

SAP Security Note #3770649, tagged with a CVSS score of 4.3, patches a Missing Authorization Check vulnerability in SAP BusinessObjects Business Intelligence Platform (Admin Tools). Our team identified certain administrative functionality that did not perform sufficient authorization checks. An attacker authenticated as a non-administrative user could gain limited information about affected functionality. This results in a low impact on confidentiality. 

Another Missing Authorization Check vulnerability was detected by the ORL in the Customer Transport Integration Wizard of the Change and Transport System in SAP NetWeaver and ABAP Platform. The vulnerability allows a low-privileged user to modify configuration tables that control access to data objects during specific operations. These unauthorized modifications could result in processing delays and operational disruption, leading to a low impact on the integrity and availability of the application. SAP Security Note #3752864, tagged with a CVSS score of 4.2, patches the issue by enforcing proper check access restrictions to the affected functions.  

The ORL team also contributed to SAP Note #3781404. Missing or insufficient authorization checks could lead to deletion of some limited data. Since the affected function modules use an deprecated function module, SAP decided to remove the consumers of that function module with this SAP Correction Note.

Summary & Conclusions

With thirty-three SAP Security Notes, including five HotNews and nine High Priority Notes, SAP’s August Patch Day is a very busy one. Special attention is required for SAP Commerce customers and customers using SAP MII. SAP has patched 2 HotNews, three High Priority and one Medium Priority vulnerability for this application – all in collaboration with our Onapsis Research Labs.

SAP NoteTypeDescriptionPriorityCVSS
3771065 New[CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
CEC-SCC-PLA-PL 
HotNews10.0
3765948New[CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence
MFG-MII
HotNews9.9
3747367Update[CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
BC-FES-ITS
HotNews9.9
3714806New[CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
BC-ABA-SC
HotNews9.8
3758900New[CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence
MFG-MII
HotNews9.1
3772411New[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools
BC-DWB-AIE-DP
High8.8
3732471Update[CVE-2026-34259] OS Command Injection Vulnerability in SAP Forecasting & Replenishment
SCM-FRE-FRP
High8.2
3773203New[CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX
CEC-SCC-CLA-ENV-EMG
High8.1
3756565New[CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
BI-BIP-SRV
High7.9
3759854New[CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence
MFG-MII
High7.6
3773304Update[CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)
BC-CTS-TMS-PLS
High7.6
3758657New[CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
MFG-MII
High7.3
3758910New[CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
MFG-MII
High7.3
3786038New[CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)
BC-XS-APR
High7
3753141New[CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence
BI-RA-WBI
Medium6.5
3770868New[CVE-2026-34480] Improper Output Encoding Vulnerability in SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core) 
CEC-SCC-PLA-PL 
Medium6.5
3757815New[CVE-2026-5598] Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library) 
CEC-SCC-PLA-PL 
Medium6.5
3758318New[CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
BC-SRV-FP
Medium6.3
3766473New[CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence
CA-EPT-SMI
Medium6.3
3721424New[CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
BC-WD-UR
Medium6.3
3772071New[CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5
CA-UI5-COR
Medium6.1
3540688Update[CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework
FI-LOC-CA-XX
Medium5.5
3745182New[CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
BC-CST-DP
Medium5.5
3725940New[CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service
BC-CCM-PRN
Medium5.3
3756674New[CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform
BC-CST-DP
Medium5.3
3778462 New[Multiple CVEs] Security Vulnerabilities in SAP Commerce Cloud (Search and Navigation)

CEC-SCC-COM-SRC-SER 
Medium4.8
3669608Update[CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
FI-FIO-AR-PAY
Medium4.3
3770649New[CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)
BI-BIP-INV
Medium4.3
3781137New[CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)
MFG-MII
Medium4.3
3413033New[CVE-2026-58246 ] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
BC-MID-ICF
Medium4.3
3752864New[CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System – Customer Transport Integration Wizard)
BC-CTS-TMS-CTR
Medium4.2
3763028New[CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
SCM-APO-PPS-MMP
Low3.8
3739913New[CVE-2026-44762 ] Security Misconfiguration in SAP Data Services Management Console
EIM-DS-DEP
Low3.7

As always, the Onapsis Research Labs is already updating The Onapsis Platform to incorporate the newly published vulnerabilities into the product so that our customers can protect their businesses.

For more information about the latest SAP security issues and our continuous efforts to share knowledge with the security community, subscribe to our monthly Defender’s Digest Onapsis Newsletter.