SAP released Security Patch Day updates to fix multiple newly disclosed vulnerabilities across its product portfolio, including two critical and six high-severity issues affecting SAP NetWeaver Application Server ABAP, SAP Manufacturing Integration and Intelligence, ABAP Developer Tools, BusinessObjects Business Intelligence Platform Central Management Server, and the SAP Business AI Platform Approuter node.js package. The vulnerabilities span arbitrary code execution, arbitrary file write, denial of service, tampering, and information disclosure, and SAP urged customers to apply the relevant security bulletins and product updates.
Among the disclosed flaws, CVE-2026-58243 affects SAP ABAP Developer Tools and carries a CVSS 8.8 rating. The vulnerability stems from missing authorization checks (CWE-862) that can let a low-privileged attacker perform unauthorized database operations against SAP NetWeaver AS ABAP over the network. Successful exploitation could expose sensitive data, alter application data, and disrupt legitimate user access. SAP identified affected SAP_BASIS versions as 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, and 920, and recommended patching, tightening database operation permissions, limiting user privileges, and monitoring logs for unauthorized activity.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
As part of its August 2026 Security Patch Day, SAP disclosed CVE-2026-34265, a critical memory corruption vulnerability in the Application Server ABAP component of SAP NetWeaver and the ABAP Platform. SAP said the flaw affects kernel versions 7.22 through 9.19 and assigned it a CVSS score of 9.8.
SAP published CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools caused by missing authorization checks. The vulnerability allows a low-privileged remote attacker to perform unauthorized database operations against SAP NetWeaver AS ABAP and is tracked with CVSS 8.8.
During its August 2026 Security Patch Day, SAP patched two critical code injection vulnerabilities in SAP Manufacturing Integration and Intelligence, tracked as CVE-2026-44772 and CVE-2026-44758. SAP said the flaws could allow arbitrary command execution on the underlying host and potentially lead to total infrastructure compromise.
During its August Patch Day, SAP released a fix for CVE-2026-58231 in SAP Commerce Cloud, a critical unauthenticated remote code execution flaw caused by insufficient validation checks. SAP rated the issue CVSS 10.0 and said successful exploitation could give attackers full control of affected cloud instances.
SAP issued its August Security Patch Day updates to address multiple newly disclosed vulnerabilities across several products. The release covered 2 critical and 6 high-severity issues, including ABAP Developer Tools, SAP NetWeaver Application Server ABAP, SAP Manufacturing Integration and Intelligence, BusinessObjects BI Platform CMS, and the SAP Business AI Platform Approuter package.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
cert.gov.py
Open sourceonapsis.com
Open sourcecybersecuritynews.com
Open sourcemalware.news
Open sourceacn.gov.it
Open sourcecvefeed.io
Open sourceme.sap.com
Open sourceme.sap.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.