【Vulnerability Alert】SAP Issues Critical Cybersecurity Advisories for Multiple Products_1150814

publish date : 2026-08-21 update date : 2026-08-21

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026081404084040 Publication Time 2026-08-14 16:11:41
Incident Type ANA-Vulnerability Alert Discovery Time 2026-08-14 16:11:41
Impact Level Low  
[Subject]
【Vulnerability Alert】SAP Issues Critical Cybersecurity Advisories for Multiple Products_1150814
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202608-00000010

SAP released its August routine updates, including 4 high-risk cybersecurity vulnerabilities.

【CVE-2026-58231, CVSS: 10.0】SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions that lack complete validation. Successful exploitation of this vulnerability may lead to arbitrary code execution and compromise internal components.

【CVE-2026-34265, CVSS: 9.8】SAP NetWeaver and ABAP Platform allow an unauthenticated attacker to exploit a logic error in DIAG protocol parsing, which may result in memory corruption, disclosure of sensitive system information, or system crashes.

【CVE-2026-44758, CVSS: 9.1】SAP Manufacturing Integration and Intelligence allows a highly privileged attacker to submit specially crafted input to certain affected functions. Without sufficient validation, successful exploitation of this vulnerability may allow the attacker to execute arbitrary commands on the underlying operating system.

【CVE-2026-58243, CVSS: 8.8】Certain functions of SAP ABAP Developer Tools do not perform the required authorization checks, allowing a lower-privileged attacker to perform unauthorized database operations on SAP NetWeaver AS ABAP. Successful exploitation of this vulnerability may allow the attacker to read sensitive data, modify application data, and disrupt access by legitimate users.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

【CVE-2026-58231】SAP Commerce Cloud (Data Hub Adapter) Version(s) - COM_CLOUD 2211, 2211-JDK21

【CVE-2026-34265】SAP NetWeaver and ABAP Platform Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19

【CVE-2026-44758】SAP Manufacturing Integration and Intelligence Version(s) - XMII 15.4, 15.5

【CVE-2026-58243】SAP ABAP Developer Tools Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920

[Recommended Actions]

Apply the patches according to the remediation instructions released on the official website: https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html?isu_page=1

[Reference]

https://www.twcert.org.tw/tw/cp-169-11102-6a741-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center