CVE Tools
Back to feed
Patch released SAP Commerce Cloud rce Manufacturing Integration and Intelligence SAP auth-bypass

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

SAP has issued its August 2026 security patch day updates, addressing four critical vulnerabilities including CVE-2026-58231, a CVSS 10/10 authentication bypass flaw in SAP Commerce Cloud that allows remote code execution. Additionally, two critical code injection vulnerabilities, CVE-2026-44772 and CVE-2026-44758, affect Manufacturing Integration and Intelligence, enabling attackers to execute arbitrary commands via vulnerable servlets.

The final critical fix, CVE-2026-34265, addresses an unauthenticated memory corruption issue in Application Server ABAP for NetWeaver that can lead to system crashes or data disclosure. Administrators should apply the latest security notes to mitigate these risks, particularly given the high exploitability of the remote code execution vectors.