SAP’s August Security Patch Day fixes four critical vulnerabilities across Commerce Cloud, Manufacturing Integration and Intelligence (MII), and NetWeaver ABAP, including CVE-2026-58231, a Commerce Cloud Data Hub Adapter auth bypass, and CVE-2026-34265, an unauthenticated memory-corruption bug in ABAP. Two more critical MII issues, CVE-2026-44772 and CVE-2026-44758, cover code-injection paths with different privilege requirements.
In the ABAP case, SAP’s DIAG protocol parser misreads a conversation packet before login and corrupts memory, so a malformed request can crash the system or potentially steer it without valid credentials. In the MII cases, the app first needs elevated access, then executes crafted input instead of handling it safely, which can turn a local foothold into control of the underlying host.
The important map detail is that these flaws do not sit at one trust boundary: some are reachable from outside the login wall, while others mainly matter where privileged users or exposed admin paths already exist. For mixed SAP estates, that means exposure and patch priority vary by component, not by the patch day as a whole.