high2026-08-11SAP Commerce CloudCVE-2026-42945

Buffer Overflow in SAP Commerce Cloud Public Cloud NGINX Layer

SAP Commerce Cloud (Public Cloud — NGINX)

Our Take

Commerce Cloud has a critical CVSS 10.0 note this month (3771065) and this CVSS 8.1 buffer overflow. Both affect the same platform — bundle them in one redeployment. If you already scheduled an emergency maintenance for the Data Hub note, add this.

Vulnerability Detail

A buffer overflow vulnerability in the NGINX layer of SAP Commerce Cloud (Public Cloud) allows an attacker to trigger memory corruption, potentially leading to denial of service or, under certain conditions, remote code execution. The vulnerability affects the embedded NGINX component in the COM_CLOUD 2211 release.

Patch Action

Apply SAP Note 3773203. Bundle with Note 3771065 (Data Hub RCE) in a single Commerce Cloud maintenance and redeployment window.

Affected Versions

COM_CLOUD 2211

Patch Info

CVSS Score

8.1

SAP Note

3773203

CVE

CVE-2026-42945

Published

2026-08-11

← All patches