SAP disclosed two high-severity vulnerabilities affecting core enterprise platforms: CVE-2026-34265 in SAP NetWeaver Application Server ABAP and CVE-2026-44758 in SAP Manufacturing Integration and Intelligence (MII). The NetWeaver flaw is an unauthenticated memory corruption issue in DIAG protocol parsing, rated CVSS 9.8, that can allow sensitive information disclosure or system crashes with high impact to confidentiality, integrity, and availability. The MII flaw is a CWE-94 code injection vulnerability affecting XMII 15.4 and 15.5; an attacker with high privileges can exploit insufficient input validation to execute arbitrary commands on the underlying operating system, with a CVSS 9.1 rating.
SAP published fixes in Security Notes 3714806 and 3758900, while reporting indicated no confirmed public exploit or proof-of-concept code at the time of publication and no inclusion in CISA's Known Exploited Vulnerabilities catalog. The disclosures prompted guidance to prioritize patching, limit exposure of the DIAG interface, and review privileged access to MII environments because successful exploitation could disrupt critical SAP operations and expose sensitive enterprise data.

See real exploitation activity before you spend the cycle.
4 events from the most recent confirmed update back to the earliest known activity.
The SAP CNA newly received CVE-2026-44758 for a code injection vulnerability in SAP Manufacturing Integration and Intelligence affecting XMII 15.4 and 15.5. The issue allows a high-privileged attacker to submit crafted input that can lead to arbitrary operating system command execution.
The SAP CNA newly received CVE-2026-34265 for a memory corruption vulnerability in SAP NetWeaver Application Server ABAP caused by logical errors in DIAG protocol parsing. The flaw can be exploited remotely without authentication and may disclose sensitive information or crash the system.
A source states that the CVE records for the SAP NetWeaver ABAP memory corruption flaw and the SAP MII code injection flaw became publicly available on August 10-11, 2026. The disclosures identified affected products, impact, and SAP references for remediation.
SAP published remediation guidance for the two vulnerabilities via Security Note 3714806 for SAP NetWeaver Application Server ABAP and Security Note 3758900 for SAP Manufacturing Integration and Intelligence. A source states the SAP security notes were published on August 10-11, 2026.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
3 references tracked. Mallory keeps watching after this page renders.
threataft.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.