August 2026 · 28 notes

Patch Intelligence

SAP Security Patches

Every SAP Security Note from Patch Tuesday, ranked by what actually matters to your landscape. Tier 1 products are in almost every SAP shop — missing a patch there is career-ending for BASIS admins.

4

Critical

8

High

14

Medium

2

Low

Severity
Timing

Tier 1 · Always covered

6 patches

Products in virtually every SAP environment. Patch these first, every month.

T12026-08-11
SAP NetWeaver

Unauthenticated Memory Corruption via DIAG Protocol in SAP NetWeaver AS ABAP

Improper boundary validation in DIAG protocol parsing within SAP NetWeaver Application Server ABAP allows an unauthenticated remote attacker to send a specially crafted network packet that triggers memory corruption. Successful exploitation can lead to disclosure of sensitive information or complete system crash — and under favourable conditions, arbitrary code execution. DIAG is the native SAP GUI network protocol used by all SAPGUI connections.

🔴Patch immediately
#3714806CVSS 9.8
T12026-08-11
SAP NetWeaver

Cross-Site Scripting in SAP NetWeaver Web Dynpro UI Repository

Cross-site scripting vulnerability in the UI Repository component of SAP NetWeaver Web Dynpro allows an attacker to inject malicious scripts that execute in the browser context of authenticated users, enabling session hijacking or credential theft.

#3721424CVSS 6.3
T12026-08-11
SAPUI5

Cross-Site Scripting in SAPUI5 Core Framework

Cross-site scripting vulnerability in the SAPUI5 Core Framework allows an attacker to inject malicious scripts through crafted UI5 content, executing in the browser context of users interacting with affected UI5-based applications — including all Fiori applications built on the affected framework version.

#3772071CVSS 6.1
T12026-08-11
SAP NetWeaver

Information Disclosure in SAP NetWeaver Internet Communication Framework

An information disclosure vulnerability in the SAP NetWeaver Internet Communication Framework (ICF) allows an authenticated attacker to access sensitive information beyond their intended permissions via the ICF request/response handling layer.

#3413033CVSS 4.3
T12026-08-11
SAP Fiori

Missing Authorization Check in SAP Fiori Accounts Receivable Payment App

A missing authorisation check in the SAP Fiori Accounts Receivable Payment application allows an authenticated user to initiate or view payment transactions beyond their intended authorisation scope.

#3669608CVSS 4.3
T12026-08-11
SAP NetWeaver

Missing Authorization Check in SAP NetWeaver CTS Transport Management System Controller

A missing authorisation check in the Transport Management System (TMS) Controller component of the SAP Change and Transport System allows an authenticated attacker to access transport management functions beyond their intended permissions.

#3752864CVSS 4.2

Tier 2 · Covered when notable

17 patches

Products with real deployments that have something worth acting on this month.

T22026-08-11
SAP Commerce Cloud

Improper Authorization in SAP Commerce Cloud Data Hub Adapter Allows Unauthenticated RCE

An improper authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter allows an unauthenticated attacker to abuse a default authentication client. Combined with specially crafted input, this enables arbitrary code execution on the underlying server — compromising confidentiality, integrity, and availability of the Commerce Cloud platform and any connected systems. Rated CVSS 10.0 — the maximum score.

🔴Patch immediately
#3771065CVSS 10
T22026-08-11
SAP Manufacturing Integration and Intelligence

Code Injection via XSL Transformation in SAP Manufacturing Integration and Intelligence

A code injection vulnerability in the XSL transformation servlet of SAP Manufacturing Integration and Intelligence (MII) allows a low-privileged attacker to submit malicious input that triggers server-side request forgery (SSRF), enabling the server to fetch attacker-controlled external content and execute arbitrary operating system commands. The attack requires only low privileges on the MII system.

🔴Patch immediately
#3765948CVSS 9.9
T22026-08-11
SAP Manufacturing Integration and Intelligence

Code Injection via XSL Transformation Servlet (IllumXSLTServlet) in SAP MII

A second code injection vulnerability in SAP Manufacturing Integration and Intelligence affects the IllumXSLTServlet component, which was susceptible to server-side template injection (SSTI). A highly privileged attacker can supply a malicious XSL template that causes the servlet to execute arbitrary operating system commands on the MII host. SAP removed the vulnerable servlet as part of the remediation.

🔴Patch immediately
#3758900CVSS 9.1
T22026-08-11
SAP ABAP Development

Privilege Escalation via Insufficient Authorization in SAP ABAP Developer Tools

Insufficient authorization checks in SAP ABAP Developer Tools (Eclipse ADT) allow a low-privileged attacker to perform unauthorized database operations that should require elevated permissions. Successful exploitation could enable an attacker to read, modify, or delete database records beyond their intended access scope.

#3772411CVSS 8.8
T22026-08-11
SAP Commerce Cloud

Buffer Overflow in SAP Commerce Cloud Public Cloud NGINX Layer

A buffer overflow vulnerability in the NGINX layer of SAP Commerce Cloud (Public Cloud) allows an attacker to trigger memory corruption, potentially leading to denial of service or, under certain conditions, remote code execution. The vulnerability affects the embedded NGINX component in the COM_CLOUD 2211 release.

#3773203CVSS 8.1
T22026-08-11
SAP BusinessObjects

Credentials Disclosure in SAP BusinessObjects BI Platform Central Management Server

A credentials disclosure vulnerability in the Central Management Server (CMS) component of SAP BusinessObjects BI Platform exposes sensitive credential material that could allow an authenticated attacker to escalate access or pivot to connected systems and data sources.

#3756565CVSS 7.9
T22026-08-11
SAP Manufacturing Integration and Intelligence

Directory Traversal in SAP Manufacturing Integration and Intelligence

A directory traversal vulnerability in SAP Manufacturing Integration and Intelligence allows an authenticated attacker to manipulate file path parameters to access files and directories outside the intended scope, potentially exposing configuration files, logs, or sensitive plant integration data.

#3759854CVSS 7.6
T22026-08-11
SAP Manufacturing Integration and Intelligence

Missing Authorization Check in SAP Manufacturing Integration and Intelligence

A missing authorisation check in SAP Manufacturing Integration and Intelligence allows an authenticated attacker to access or manipulate MII resources beyond their intended permissions, impacting the integrity of manufacturing data and plant integrations.

#3758657CVSS 7.3
T22026-08-11
SAP Manufacturing Integration and Intelligence

Missing Authorization Check in SAP MII (Second Instance)

A second missing authorisation check vulnerability in SAP Manufacturing Integration and Intelligence — a distinct component from Note 3758657 — allows authenticated access to restricted MII functionality. The two missing-auth notes reflect different access control gaps within the same platform.

#3758910CVSS 7.3
T22026-08-11
SAP Approuter

Multiple Vulnerabilities in SAP Approuter — Credential Exfiltration via Token Validation

SAP Security Note 3786038 addresses eleven distinct vulnerabilities in SAP Approuter. The lead CVE (CVE-2026-58230) involves insufficient token content validation under specific configurations — an unauthenticated attacker can send a specially crafted token that causes the Approuter to forward sensitive credential material to an attacker-controlled destination. Additional vulnerabilities cover IAS, WebSocket, Redis, back-channel logout, and subscription-management flows.

#3786038CVSS 7
T22026-08-11
SAP BusinessObjects

XML External Entity Injection in SAP BusinessObjects Web Intelligence

XML External Entity (XXE) injection vulnerability in SAP BusinessObjects Web Intelligence allows an authenticated attacker to submit a crafted XML document that causes the server to process external entity references, potentially leading to server-side request forgery, file disclosure, or denial of service.

#3753141CVSS 6.5
T22026-08-11
SAP NetWeaver

Vulnerable Third-Party Component in SAP NetWeaver Forms Processing

A vulnerable third-party library dependency in the SAP NetWeaver Forms Processing (Adobe Document Services) component introduces a security risk. The specific library and vulnerability class are documented in the SAP Note.

#3758318CVSS 6.3
T22026-08-11
SAP NetWeaver

OS Command Injection in SAP NetWeaver Component BC-CST-DP

An OS command injection vulnerability in the BC-CST-DP component of SAP NetWeaver allows an authenticated attacker to inject operating system commands through unsanitised input, with potential for arbitrary command execution on the application server.

#3745182CVSS 5.5
T22026-08-11
SAP NetWeaver

Memory Corruption in SAP NetWeaver Component BC-CST-DP

A memory corruption vulnerability in the BC-CST-DP component of SAP NetWeaver allows an attacker to trigger abnormal memory conditions, potentially causing service disruption or unexpected system behaviour.

#3756674CVSS 5.3
T22026-08-11
SAP NetWeaver

Memory Corruption in SAP SAPSPrint Service

A memory corruption vulnerability in the SAPSPrint Service component of SAP NetWeaver allows an attacker to trigger abnormal memory conditions, potentially causing the print service to crash or behave unexpectedly.

#3725940CVSS 5.3
T22026-08-11
SAP BusinessObjects

Missing Authorization Check in SAP BusinessObjects BI Platform

A missing authorisation check in the SAP BusinessObjects BI Platform allows an authenticated user to access BI resources or administrative functions beyond their intended permissions.

#3770649CVSS 4.3
T22026-08-11
SAP Manufacturing Integration and Intelligence

Missing Authorization Check in SAP MII (Medium Severity)

A missing authorisation check in SAP Manufacturing Integration and Intelligence allows an authenticated attacker to access MII functionality beyond their intended scope. This is distinct from the two high-severity missing-auth notes (3758657, 3758910) and affects a different MII component.

#3781137CVSS 4.3

Tier 3 · Critical CVEs only

5 patches

Niche or SaaS-only products. Covered here when severity warrants it.

T32026-08-11
SAP SCM

OS Command Injection in SAP Forecasting and Replenishment

An OS command injection vulnerability in SAP Forecasting and Replenishment allows an authenticated attacker to inject operating system commands through unsanitised input, achieving arbitrary command execution on the underlying server. This compromises the integrity and availability of the F&R system and potentially the systems it integrates with.

#3732471CVSS 8.2
T32026-08-11
SAP

SQL Injection in SAP Application Component CA-EPT-SMI

SQL injection vulnerability in the CA-EPT-SMI application component of SAP allows an authenticated attacker to inject malicious SQL statements, potentially accessing or modifying data beyond their intended authorisation.

#3766473CVSS 6.3
T32026-08-11
SAP Financial Accounting

Code Injection in SAP Financial Accounting Localization

A code injection vulnerability (originally assigned CVE-2025-42947) in the SAP Financial Accounting Localization component is being patched in August 2026. The vulnerability allows an authenticated attacker to inject code through localization-specific functionality, with potential for data manipulation in country-specific financial processes.

#3540688CVSS 5.5
T32026-08-11
SAP SCM

Hard-coded Credentials in SAP Advanced Planning and Optimization Model Mix Planning

Hard-coded credentials exist in the Model Mix Planning component of SAP Advanced Planning and Optimization (APO). These embedded credentials could be discovered and used by an attacker to gain unauthorised access to the component.

#3763028CVSS 3.8
T32026-08-11
SAP

Security Misconfiguration in SAP Data Intelligence Deployment

A security misconfiguration in the deployment component of SAP Data Intelligence exposes configuration or operational details that should not be accessible, potentially aiding reconnaissance or further exploitation.

#3739913CVSS 3.7