medium2026-08-11SAP NetWeaverCVE-2026-58247

Memory Corruption in SAP NetWeaver Component BC-CST-DP

SAP NetWeaver (BC-CST-DP)

Our Take

Second note for BC-CST-DP this month — OS command injection (3745182) and memory corruption (3756674). Bundle both.

Vulnerability Detail

A memory corruption vulnerability in the BC-CST-DP component of SAP NetWeaver allows an attacker to trigger abnormal memory conditions, potentially causing service disruption or unexpected system behaviour.

Patch Action

Apply SAP Note 3756674. Bundle with Note 3745182 (same component) in a single patch.

Patch Info

CVSS Score

5.3

SAP Note

3756674

CVE

CVE-2026-58247

Published

2026-08-11

← All patches