Raghu Boddu,August 11, 2026 24
FREE – Anyone can read

SAP August 2026 Security Notes: 4 Critical, 8 High and 17 Medium Risks

SAP Security Patch Day · August 2026

4 Critical. 8 High. 17 Medium. 2 Low.

SAP Security Patch Day – August 2026 is here. And this month’s release is a good reminder that SAP security is becoming much bigger than users, roles and Segregation of Duties.

Severity Risks Addressed
Critical 4
High 8
Medium 17
Low 2
Total 31

The bigger story? These vulnerabilities span SAP Commerce Cloud, SAP MII, SAP NetWeaver and ABAP Platform, SAP BusinessObjects, SAPUI5, SAP S/4HANA and SAP Business AI Platform.

On August 11, SAP released 28 new security notes and one GitHub security advisory, along with two updates to previously released security notes. The release addresses 4 Critical, 8 High, 17 Medium and 2 Low severity risks.

At first glance, that looks like another monthly patching exercise. It isn't.

Look a little closer and you’ll see vulnerabilities across SAP Commerce Cloud, SAP Manufacturing Integration and Intelligence (MII), SAP NetWeaver and ABAP Platform, SAP BusinessObjects, SAPUI5, SAP S/4HANA, SAP Business AI Platform and other components.

That tells us something important:

The SAP attack surface is getting wider.

And that changes how SAP security teams need to think about patching.

The highest-rated vulnerability this month carries a CVSS score of 10.0.

But the number that deserves the most attention isn't necessarily 10.0.

It is the range of SAP technologies affected.

1. Four Critical vulnerabilities need immediate attention

The four Critical vulnerabilities are spread across SAP Commerce Cloud, SAP Manufacturing Integration and Intelligence, and SAP NetWeaver/ABAP Platform.

SAP Commerce Cloud: CVSS 10.0

The highest-rated issue is CVE-2026-58231, an improper authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter.

It has a CVSS score of 10.0 and affects Commerce Cloud 2211 and 2211-JDK21.

Authorization problems deserve particular attention because they can turn a legitimate identity into an unintended path to functionality or data.

This is why SAP security teams should not look at vulnerabilities in isolation.

A vulnerability becomes much more interesting when you combine it with:

  • Who can reach the system?
  • What identity is required?
  • What access does that identity have?
  • What data or applications are connected to it?

That context determines the real business risk.

2. SAP MII has two Critical code injection vulnerabilities

SAP Manufacturing Integration and Intelligence appears prominently in this month's release.

Two Critical vulnerabilities involve code injection:

  • CVE-2026-44772 - CVSS 9.9
  • CVE-2026-44758 - CVSS 9.1

Both affect SAP Manufacturing Integration and Intelligence versions listed by SAP.

This is particularly important for organizations using SAP in manufacturing environments.

MII doesn't exist in isolation.

It can sit alongside manufacturing systems, enterprise applications, integrations and operational processes.

That means a vulnerability here should not be treated simply as:

"An MII patch."

It should be treated as a potential part of an enterprise attack path.

3. ABAP and NetWeaver: Critical memory corruption vulnerability

The fourth Critical vulnerability is CVE-2026-34265, a memory corruption vulnerability affecting the Application Server ABAP for SAP NetWeaver and ABAP Platform.

It carries a CVSS score of 9.8 and affects multiple SAP kernel versions.

For organizations with large ABAP landscapes, this is one of the issues that should move quickly through the assessment and remediation process.

The important point is simple:

Don't wait for the next patch cycle to decide what to do with a Critical vulnerability.

First determine whether you are affected. Then determine how exposed the affected systems are.Then prioritize remediation.

4. The High-severity vulnerabilities are worth a closer look

August also brings 8 High-severity vulnerabilities.

They include issues affecting:

  • SAP ABAP Developer Tools
  • SAP Commerce Cloud
  • SAP Change and Transport System Attach Tool
  • SAP BusinessObjects
  • SAP Manufacturing Integration and Intelligence
  • SAP Business AI Platform

One of them is a privilege escalation vulnerability in SAP ABAP Developer Tools, rated CVSS 8.8.

Another is a Remote Code Execution vulnerability in the SAP Change and Transport System Attach Tool (ctsattach), rated CVSS 7.6. SAP identifies this as an update to a security note released during the July 2026 Patch Day.

That last point is easy to overlook.

And it matters.

5. Security notes don't stop changing after Patch Day

One of the most useful reminders from this month's release is that SAP has also updated previously released security notes.

In other words, your monthly process shouldn't be:

"What new notes did SAP release?"

It should be:

"What changed in SAP's security guidance that affects my landscape?"

A security note released last month can be updated this month. So a mature SAP vulnerability-management process should look at:

New notes + updated notes + affected systems + exposure + remediation status.

That's a much better approach than simply downloading the monthly SAP note list.

6. SAP MII is a clear theme this month

There is another pattern worth noticing.

SAP MII appears multiple times across the August release.

Along with the two Critical code injection vulnerabilities, SAP lists High-severity vulnerabilities involving directory traversal and missing authorization checks, as well as another Medium-severity missing authorization issue.

If your organization runs MII, this is a good month to ask a basic question:

Do we have a complete inventory of where MII is deployed and how it connects to the rest of our SAP landscape?

It sounds obvious.

In practice, large SAP environments are rarely that simple.

  • Systems get added.
  • Integrations remain after projects end.
  • Components get upgraded.
  • Cloud services get introduced.

And security teams don't always have the same level of visibility across every layer.

That is exactly why vulnerability management needs good asset visibility behind it.

7. Medium severity doesn't automatically mean low risk

There are 17 Medium-severity vulnerabilities in the August release.

And this is where many SAP security teams can fall into a trap.

  • Critical gets patched.
  • High gets reviewed.
  • Medium gets added to a backlog.
  • Sometimes that's perfectly reasonable.

But CVSS severity and business risk are not the same thing.

This month's Medium vulnerabilities include issues involving:

  • XSS
  • SQL injection
  • OS command injection
  • Memory corruption
  • Missing authorization checks
  • Vulnerable third-party components
  • Security-related weaknesses in SAP applications and services

For example, SAP lists an XSS vulnerability in SAP NetWeaver AS ABAP and another XSS vulnerability in SAPUI5. It also lists a SQL injection vulnerability in SAP Social Intelligence and an OS command injection vulnerability in SAP NetWeaver/ABAP Platform.

So don't ask only:

"What is the CVSS score?"

Ask:

"Where is this vulnerability running in my environment?"

A Medium vulnerability on an isolated, low-value system is one thing.

The same vulnerability on a business-critical system with sensitive data and broad connectivity can be a very different story.

8. SAP Business AI Platform is now part of the conversation

Another interesting element of the August release is the presence of vulnerabilities in the SAP Business AI Platform (Approuter).

SAP rates the issue High, with a CVSS score of 7.0, and lists multiple associated CVEs.

This is worth watching beyond this month's patch.

Why?

Because SAP environments are changing.

The traditional SAP landscape was largely centered around ERP, databases, users, roles and applications.

Today's landscape increasingly includes:

APIs → Cloud applications → SaaS → Integrations → AI services → External platforms

The security boundary is moving.

And SAP security teams need to move with it.

9. SAP security is no longer just about GRC

This is perhaps the biggest takeaway from August's Security Patch Day.

For years, many SAP security programs were built around:

  • Users
  • Roles
  • Transactions
  • Authorizations
  • SoD
  • Access Reviews

Those controls are still important.

But they don't tell the whole story.

A modern SAP security program needs visibility across:

  • Identity
  • Authorization
  • Vulnerabilities
  • Configuration
  • APIs
  • Integrations
  • Cloud services
  • Applications
  • Monitoring
  • Detection and Response

And increasingly:

AI

That doesn't mean GRC is becoming irrelevant.

It means GRC is becoming one part of a much larger SAP security program.

10. What should SAP security teams do now?

If you are responsible for SAP security, here is a practical way to approach this month's release.

Step 1: Map the vulnerabilities to your landscape

Don't start by patching everything.

Start by answering:

Which products and versions do we actually run?

Check your SAP landscape against the affected products and versions listed in the August security notes.

Step 2: Start with the four Critical vulnerabilities

Prioritize the four Critical vulnerabilities first:

  • SAP Commerce Cloud - CVSS 10.0
  • SAP MII - CVSS 9.9
  • SAP NetWeaver/ABAP Platform - CVSS 9.8
  • SAP MII - CVSS 9.1

Determine whether you are affected and what remediation path applies.

Step 3: Review the High vulnerabilities based on exposure

Don't treat every High vulnerability identically.

Ask:

  • Is the system internet-facing?
  • Is authentication required?
  • What privileges are needed?
  • What data does the system contain?
  • What systems does it connect to?
  • Can the vulnerability be combined with existing access?
  • Are compensating controls already in place?

This turns patching into risk-based vulnerability management.

Step 4: Don't automatically push Medium vulnerabilities aside

Use business context.

A Medium vulnerability on a highly connected production system may deserve faster attention than a High vulnerability on an isolated development environment.

The number on the CVSS score is important.

But context completes the picture.

Step 5: Validate the fix

Applying the patch isn't the final step.

After remediation, verify that:

  • The affected component was actually updated.
  • The vulnerable version is no longer present.
  • The security note was correctly implemented.
  • The system still functions as expected.
  • No new authorization or configuration issues were introduced.

This is where vulnerability management becomes a continuous process rather than a monthly administrative task.

The bigger lesson from SAP Security Patch Day - August 2026

August's release isn't interesting simply because there are 4 Critical vulnerabilities.

It's interesting because of where those vulnerabilities are appearing.

  • Commerce Cloud.
  • Manufacturing.
  • ABAP.
  • BusinessObjects.
  • SAPUI5.
  • S/4HANA.
  • Business AI.
  • Different technologies.
  • Different attack surfaces.
  • Different potential attack paths.

And that tells us something important about SAP security in 2026.

Your SAP security boundary is no longer your SAP system.

It is the ecosystem around it.

  • The applications.
  • The APIs.
  • The integrations.
  • The cloud services.
  • The identities.
  • The underlying components.

And increasingly, the AI services being connected to the enterprise.

So the question shouldn't simply be:

"Did we apply the August SAP Security Notes?"

A better question is:

"Do we know which August vulnerabilities affect us, how exposed we are, and what an attacker could do if one of them were exploited?"

That's the difference between patch management and SAP vulnerability management.

And that's the bigger message from SAP Security Patch Day – August 2026.

  • Patch the vulnerability.
  • Understand the exposure.
  • Know the attack path.
  • And keep looking beyond the patch list.

Source: SAP Security Patch Day – August 2026. SAP recommends customers review the security notes in the SAP Support Portal and apply patches according to priority.

Read more: SAP Security Patch Day – August 2026

Frequently Asked Questions

How many vulnerabilities did SAP address in August 2026?

SAP's August 2026 Security Patch Day addresses 4 Critical, 8 High, 17 Medium and 2 Low severity risks. SAP's release includes 28 new security notes, one GitHub security advisory and two updates to previously released security notes.

What is the most critical SAP vulnerability in August 2026?

The highest-rated vulnerability is CVE-2026-58231, an improper authorization vulnerability in SAP Commerce Cloud's Data Hub Adapter, with a CVSS score of 10.0.

Which SAP products have Critical vulnerabilities in August 2026?

The four Critical vulnerabilities affect SAP Commerce Cloud, SAP Manufacturing Integration and Intelligence (MII), and SAP NetWeaver/ABAP Platform.

Does SAP Security Patch Day only affect SAP S/4HANA?

No. The August 2026 release affects a broad range of SAP technologies, including Commerce Cloud, MII, NetWeaver/ABAP Platform, BusinessObjects, SAPUI5, S/4HANA and SAP Business AI Platform.

Should Medium-severity SAP vulnerabilities be patched immediately?

Not necessarily. Organizations should prioritize vulnerabilities based on both severity and environmental context, including exposure, system criticality, privileges, sensitive data and available compensating controls.

Raghu Boddu

Raghu Boddu

SAP Security Architect & ERP Cybersecurity Authority

Raghu Boddu is a technology leader and cybersecurity professional specializing in SAP Security, GRC, data protection, and enterprise risk management. He is the author of SAP Press books on SAP Access Control, SAP Process Control, and SAP Identity Access Governance (IAG). Raghu focuses on building practical, automation-driven solutions that help organizations achieve secure, compliant, and audit-ready operations across SAP and cloud landscapes. He regularly shares independent insights and hands-on experience for practitioners and leaders navigating evolving cybersecurity and regulatory challenges.

SAP August 2026 Security Notes: 4 Critical, 8 High and 17 Medium Risks | SAP Security Expert