SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP has issued its August 2026 security patch day updates, addressing four critical vulnerabilities including CVE-2026-58231, a CVSS 10/10 authentication bypass flaw in SAP Commerce Cloud that allows remote code execution. Additionally, two critical code injection vulnerabilities, CVE-2026-44772 and CVE-2026-44758, affect Manufacturing Integration and Intelligence, enabling attackers to execute arbitrary commands via vulnerable servlets.
The final critical fix, CVE-2026-34265, addresses an unauthenticated memory corruption issue in Application Server ABAP for NetWeaver that can lead to system crashes or data disclosure. Administrators should apply the latest security notes to mitigate these risks, particularly given the high exploitability of the remote code execution vectors.