high2026-08-11SAP Commerce CloudCVE-2026-42945
Buffer Overflow in SAP Commerce Cloud Public Cloud NGINX Layer
SAP Commerce Cloud (Public Cloud — NGINX)
Our Take
Commerce Cloud has a critical CVSS 10.0 note this month (3771065) and this CVSS 8.1 buffer overflow. Both affect the same platform — bundle them in one redeployment. If you already scheduled an emergency maintenance for the Data Hub note, add this.
Vulnerability Detail
A buffer overflow vulnerability in the NGINX layer of SAP Commerce Cloud (Public Cloud) allows an attacker to trigger memory corruption, potentially leading to denial of service or, under certain conditions, remote code execution. The vulnerability affects the embedded NGINX component in the COM_CLOUD 2211 release.
Patch Action
Apply SAP Note 3773203. Bundle with Note 3771065 (Data Hub RCE) in a single Commerce Cloud maintenance and redeployment window.
Affected Versions
COM_CLOUD 2211
Patch Info