Security News

Cybersecurity news aggregator

🔓
CRITICAL Vulnerabilities SecurityWeek

SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

SAP's August 2026 Security Patch Day addresses four critical vulnerabilities, including CVE-2026-58231 (CVSS 10.0), an improper authorization flaw in SAP Commerce Cloud allowing authentication bypass and potential code execution. Two critical code injection flaws in Manufacturing Integration and Intelligence (CVE-2026-44772 and CVE-2026-44758) allow authenticated attackers to execute arbitrary commands via crafted servlet input, while a critical memory corruption bug in Application Server ABAP (CVE-2026-34265) can be exploited without authentication to crash systems or leak data. SAP has released patches for these issues; specific affected and fixed version numbers are not detailed in the provided text.
Read Full Article →

Vulnerabilities SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. By Ionut Arghire | August 11, 2026 (10:14 AM ET) Flipboard Reddit Whatsapp Whatsapp Email Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory. Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most severe of which is CVE-2026-58231 (CVSS score of 10/10), an improper authorization issue in SAP Commerce Cloud (Data Hub Adapter). The bug could allow remote attackers to bypass authentication, likely leading to code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the application. SAP also addressed two critical code injection flaws in Manufacturing Integration and Intelligence, tracked as CVE-2026-44772 (CVSS score of 9.9/10) and CVE-2026-44758 (CVSS score of 9.1/10). Vulnerable servlets allow attackers to submit specially crafted input, leading to the execution of arbitrary commands on the underlying host and total infrastructure compromise. While the bugs are similar, one requires higher privileges to be exploited, application security firm Onapsis explains . The fourth critical defect is CVE-2026-34265 (CVSS score of 9.8/10), which is described as a memory corruption issue in Application Server ABAP for NetWeaver and ABAP Platform. Advertisement. Scroll to continue reading. Rooted in logical errors in DIAG protocol parsing, the vulnerability can be exploited without authentication to disclose sensitive information or crash the system, impacting application confidentiality, integrity, and availability. Before this month’s patches, SAP updated a critical security note released on the July 2026 Patch Day to resolve a critical memory corruption bug in NetWeaver Application Server ABAP. The update contains additional information. On Tuesday, SAP also released eight notes dealing with high-severity flaws in ABAP Developer Tools, Commerce Cloud, Change and Transport System Attach Tool, BusinessObjects, Manufacturing Integration and Intelligence, and Business AI Platform (Approuter). The first seven notes deal with privilege escalation, buffer overflow, remote code execution (RCE), credentials disclosure, directory traversal, and missing authorization check issues, while the seventh resolves 11 security defects in Approuter. The remaining notes released on SAP’s August 2026 Patch Day resolve medium- and low-severity vulnerabilities. SAP makes no mention of any of these flaws being exploited in the wild. Related: Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC Related: Metabase Patches Vulnerability Exploited as Zero-Day Related: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Related: Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC ‘Ghostjacking’ Attack Uses Poisoned Logs to Turn AI Agents Bad Metabase Patches Vulnerability Exploited as Zero-Day CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability Corporate Data Stolen in Levi Strauss Cyberattack Vishing Extortion Group UNC6671 Rebrands After Making Millions Microsoft, Apple Release Fresh Security Updates 3.8 Million Impacted by Unlimited Technology Systems Data Breach Latest News US Water Systems Get Cyber Boost From New Senate Bill and ‘Water Watch Center’ Corma Raises $60 Million for Defensive Cybersecurity AI Model Extension Banned for Stealing AI Chats Returns to Chrome Store, Resumes Malicious Activities Hacker Conversations: Marcus Hutchins and the Journey From the Gray Zone to Redemption OpenAI Unveils New Cybersecurity Model GPT-5.6-Cyber Mozilla Issues New Firefox GPG Key Following Exposure OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns Stealthium Targets Security Blind Spots in AI Accelerators and Neo-Clouds Trending Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Rethinking Cyber Defense for AI-Speed Attacks August 18, 2026 Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default. Register Virtual Event: CodeSecCon 2026 August 19, 2026 CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps! Register People on the Move 1Kosmos has named Frank Cohen Chief Revenue Officer. ServiceNow has appointed Simon Mouyal as Chief Marketing Officer. James Wilkinson has been named Chief Information Security Officer for the City of Dallas. More People On The Move Expert Insights Rethinking AI Security: Why CASB and DLP Need an Interaction-Aware Layer Build your strategy around answering these questions to ensure employees use AI productively while keeping sensitive data, IP, and agent behavior within the boundaries set for safe AI use. (Etay Maor) Timeless Compliance: Why Better Questions Beat Bigger Frameworks The best compliance programs aren't the biggest ones. They're the ones built on a short list of questions that can actually be answered, and that still hold true when the models change. (Matt Honea) Is Patching Dead? Vulnerability Management in the Post-Mythos Era You cannot out-patch a machine that writes a working exploit from a vulnerability description in twenty hours. Stop trying to optimize a game you cannot win. (Danelle Au) When Identity Verification Fails: Lessons from a Real-World SIM Swap and Near Account Takeover Identity confidence changes throughout every interaction and should be reassessed continuously as new risk signals emerge. (Torsten George) Legacy Systems, Real-World Impacts: The Reality of OT Security Legacy systems, safety concerns, and critical infrastructure risks make OT vulnerability disclosure one of cybersecurity's most challenging balancing acts. (Tod Beardsley) Flipboard Reddit Whatsapp Whatsapp Email

Share this article