August 2026 · 28 notes
Patch IntelligenceSAP Security Patches
Every SAP Security Note from Patch Tuesday, ranked by what actually matters to your landscape. Tier 1 products are in almost every SAP shop — missing a patch there is career-ending for BASIS admins.
4
Critical
8
High
14
Medium
2
Low
Tier 1 · Always covered
Products in virtually every SAP environment. Patch these first, every month.
Unauthenticated Memory Corruption via DIAG Protocol in SAP NetWeaver AS ABAP
Improper boundary validation in DIAG protocol parsing within SAP NetWeaver Application Server ABAP allows an unauthenticated remote attacker to send a specially crafted network packet that triggers memory corruption. Successful exploitation can lead to disclosure of sensitive information or complete system crash — and under favourable conditions, arbitrary code execution. DIAG is the native SAP GUI network protocol used by all SAPGUI connections.
Cross-Site Scripting in SAP NetWeaver Web Dynpro UI Repository
Cross-site scripting vulnerability in the UI Repository component of SAP NetWeaver Web Dynpro allows an attacker to inject malicious scripts that execute in the browser context of authenticated users, enabling session hijacking or credential theft.
Cross-Site Scripting in SAPUI5 Core Framework
Cross-site scripting vulnerability in the SAPUI5 Core Framework allows an attacker to inject malicious scripts through crafted UI5 content, executing in the browser context of users interacting with affected UI5-based applications — including all Fiori applications built on the affected framework version.
Information Disclosure in SAP NetWeaver Internet Communication Framework
An information disclosure vulnerability in the SAP NetWeaver Internet Communication Framework (ICF) allows an authenticated attacker to access sensitive information beyond their intended permissions via the ICF request/response handling layer.
Missing Authorization Check in SAP Fiori Accounts Receivable Payment App
A missing authorisation check in the SAP Fiori Accounts Receivable Payment application allows an authenticated user to initiate or view payment transactions beyond their intended authorisation scope.
Missing Authorization Check in SAP NetWeaver CTS Transport Management System Controller
A missing authorisation check in the Transport Management System (TMS) Controller component of the SAP Change and Transport System allows an authenticated attacker to access transport management functions beyond their intended permissions.
Tier 2 · Covered when notable
Products with real deployments that have something worth acting on this month.
Improper Authorization in SAP Commerce Cloud Data Hub Adapter Allows Unauthenticated RCE
An improper authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter allows an unauthenticated attacker to abuse a default authentication client. Combined with specially crafted input, this enables arbitrary code execution on the underlying server — compromising confidentiality, integrity, and availability of the Commerce Cloud platform and any connected systems. Rated CVSS 10.0 — the maximum score.
Code Injection via XSL Transformation in SAP Manufacturing Integration and Intelligence
A code injection vulnerability in the XSL transformation servlet of SAP Manufacturing Integration and Intelligence (MII) allows a low-privileged attacker to submit malicious input that triggers server-side request forgery (SSRF), enabling the server to fetch attacker-controlled external content and execute arbitrary operating system commands. The attack requires only low privileges on the MII system.
Code Injection via XSL Transformation Servlet (IllumXSLTServlet) in SAP MII
A second code injection vulnerability in SAP Manufacturing Integration and Intelligence affects the IllumXSLTServlet component, which was susceptible to server-side template injection (SSTI). A highly privileged attacker can supply a malicious XSL template that causes the servlet to execute arbitrary operating system commands on the MII host. SAP removed the vulnerable servlet as part of the remediation.
Privilege Escalation via Insufficient Authorization in SAP ABAP Developer Tools
Insufficient authorization checks in SAP ABAP Developer Tools (Eclipse ADT) allow a low-privileged attacker to perform unauthorized database operations that should require elevated permissions. Successful exploitation could enable an attacker to read, modify, or delete database records beyond their intended access scope.
Buffer Overflow in SAP Commerce Cloud Public Cloud NGINX Layer
A buffer overflow vulnerability in the NGINX layer of SAP Commerce Cloud (Public Cloud) allows an attacker to trigger memory corruption, potentially leading to denial of service or, under certain conditions, remote code execution. The vulnerability affects the embedded NGINX component in the COM_CLOUD 2211 release.
Credentials Disclosure in SAP BusinessObjects BI Platform Central Management Server
A credentials disclosure vulnerability in the Central Management Server (CMS) component of SAP BusinessObjects BI Platform exposes sensitive credential material that could allow an authenticated attacker to escalate access or pivot to connected systems and data sources.
Directory Traversal in SAP Manufacturing Integration and Intelligence
A directory traversal vulnerability in SAP Manufacturing Integration and Intelligence allows an authenticated attacker to manipulate file path parameters to access files and directories outside the intended scope, potentially exposing configuration files, logs, or sensitive plant integration data.
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
A missing authorisation check in SAP Manufacturing Integration and Intelligence allows an authenticated attacker to access or manipulate MII resources beyond their intended permissions, impacting the integrity of manufacturing data and plant integrations.
Missing Authorization Check in SAP MII (Second Instance)
A second missing authorisation check vulnerability in SAP Manufacturing Integration and Intelligence — a distinct component from Note 3758657 — allows authenticated access to restricted MII functionality. The two missing-auth notes reflect different access control gaps within the same platform.
Multiple Vulnerabilities in SAP Approuter — Credential Exfiltration via Token Validation
SAP Security Note 3786038 addresses eleven distinct vulnerabilities in SAP Approuter. The lead CVE (CVE-2026-58230) involves insufficient token content validation under specific configurations — an unauthenticated attacker can send a specially crafted token that causes the Approuter to forward sensitive credential material to an attacker-controlled destination. Additional vulnerabilities cover IAS, WebSocket, Redis, back-channel logout, and subscription-management flows.
XML External Entity Injection in SAP BusinessObjects Web Intelligence
XML External Entity (XXE) injection vulnerability in SAP BusinessObjects Web Intelligence allows an authenticated attacker to submit a crafted XML document that causes the server to process external entity references, potentially leading to server-side request forgery, file disclosure, or denial of service.
Vulnerable Third-Party Component in SAP NetWeaver Forms Processing
A vulnerable third-party library dependency in the SAP NetWeaver Forms Processing (Adobe Document Services) component introduces a security risk. The specific library and vulnerability class are documented in the SAP Note.
OS Command Injection in SAP NetWeaver Component BC-CST-DP
An OS command injection vulnerability in the BC-CST-DP component of SAP NetWeaver allows an authenticated attacker to inject operating system commands through unsanitised input, with potential for arbitrary command execution on the application server.
Memory Corruption in SAP NetWeaver Component BC-CST-DP
A memory corruption vulnerability in the BC-CST-DP component of SAP NetWeaver allows an attacker to trigger abnormal memory conditions, potentially causing service disruption or unexpected system behaviour.
Memory Corruption in SAP SAPSPrint Service
A memory corruption vulnerability in the SAPSPrint Service component of SAP NetWeaver allows an attacker to trigger abnormal memory conditions, potentially causing the print service to crash or behave unexpectedly.
Missing Authorization Check in SAP BusinessObjects BI Platform
A missing authorisation check in the SAP BusinessObjects BI Platform allows an authenticated user to access BI resources or administrative functions beyond their intended permissions.
Missing Authorization Check in SAP MII (Medium Severity)
A missing authorisation check in SAP Manufacturing Integration and Intelligence allows an authenticated attacker to access MII functionality beyond their intended scope. This is distinct from the two high-severity missing-auth notes (3758657, 3758910) and affects a different MII component.
Tier 3 · Critical CVEs only
Niche or SaaS-only products. Covered here when severity warrants it.
OS Command Injection in SAP Forecasting and Replenishment
An OS command injection vulnerability in SAP Forecasting and Replenishment allows an authenticated attacker to inject operating system commands through unsanitised input, achieving arbitrary command execution on the underlying server. This compromises the integrity and availability of the F&R system and potentially the systems it integrates with.
SQL Injection in SAP Application Component CA-EPT-SMI
SQL injection vulnerability in the CA-EPT-SMI application component of SAP allows an authenticated attacker to inject malicious SQL statements, potentially accessing or modifying data beyond their intended authorisation.
Code Injection in SAP Financial Accounting Localization
A code injection vulnerability (originally assigned CVE-2025-42947) in the SAP Financial Accounting Localization component is being patched in August 2026. The vulnerability allows an authenticated attacker to inject code through localization-specific functionality, with potential for data manipulation in country-specific financial processes.
Hard-coded Credentials in SAP Advanced Planning and Optimization Model Mix Planning
Hard-coded credentials exist in the Model Mix Planning component of SAP Advanced Planning and Optimization (APO). These embedded credentials could be discovered and used by an attacker to gain unauthorised access to the component.
Security Misconfiguration in SAP Data Intelligence Deployment
A security misconfiguration in the deployment component of SAP Data Intelligence exposes configuration or operational details that should not be accessible, potentially aiding reconnaissance or further exploitation.