SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0) — Threadlinqs Intelligence
As of 2026-08-16, SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0) is a critical-severity vulnerability threat, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 27 indicators of compromise.
Threat ID: TL-2026-1984 · Severity: CRITICAL · CVSS: 10 · Status: ACTIVE · Category: VULNERABILITY
Updated: 2026-08-16 · 3 updates · revalidated 3× · latest source
SAP's August 11, 2026 Security Patch Day shipped 28 new security notes, 2 updates, and 1 GitHub security advisory, including four critical-severity fixes. CVE-2026-58231 (CVSS 10.0) is an
On August 11, 2026, SAP's monthly Security Patch Day released 28 new security notes, 2 updates to prior notes, and 1 GitHub security advisory. Four of the new notes are rated critical.
The most severe, CVE-2026-58231 (CVSS v3.1: 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-94 Improper Control of Generation of Code / Code Injection, per NVD's published record), affects the Data Hub Adapter component of SAP Commerce Cloud (COM_CLOUD 2211 and 2211-JDK21). An unauthenticated remote attacker can abuse a default authentication client and submit specially crafted input to functions that lack sufficient validation, bypassing authorization to reach internal components and likely execute arbitrary code. SAP published the fix as Security Note 3771065; NVD lists the publication date as August 11, 2026.
CVE-2026-34265 (CVSS v3.1: 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-787 Out-of-bounds Write) is a memory-corruption vulnerability in SAP NetWeaver/ABAP Platform's Application Server ABAP, caused by logical errors in DIAG protocol parsing. It is exploitable by an unauthenticated network attacker and can disclose sensitive system information or crash the affected process. NVD's confirmed affected build list is: KRNL64NUC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, and KERNEL/ABAP Platform builds 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, and 9.19; the fix is documented in SAP Security Note 3714806. NVD's publication timestamp for this record (August 10, 2026) is one day ahead of SAP's coordinated August 11 Patch Day announcement, a UTC-boundary artifact seen across SAP's monthly disclosures.
CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS v3.1: 9.1, AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, CWE-94) are code-injection flaws in SAP Manufacturing Integration and Intelligence (MII; affected as XMII 15.4/15.5 for CVE-2026-44758). Both require an attacker to already hold elevated ('high') privileges within the application; SecurityWeek's analysis further distinguishes that CVE-2026-44772 needs only 'standard' privileges while CVE-2026-44758 requires a higher privilege level, consistent with the PR:H CVSS component on -44758. In both cases, vulnerable servlets process crafted input without sufficient validation, resulting in execution of arbitrary commands on the underlying host OS. The CVSS Scope-Changed (S:C) rating on CVE-2026-44758 reflects that impact extends beyond the vulnerable MII component to the host OS. SAP's fix for CVE-2026-44758 is documented in Security Note 3758900 (NVD publication timestamp August 10, 2026); CVE-2026-44772 remains a RESERVED-only CVE ID with no published NVD record at time of research (confirmed via direct NVD and CVE.org lookups), so only the vendor/press-reported CVSS and vulnerability class are confirmed.
SAP made no mention of in-the-wild exploitation for any of the four CVEs, and as of the CISA KEV catalog's August 10, 2026 release (catalog version 2026.08.10, 1,662 entries, confirmed by direct fetch), none of the four are listed as known-exploited. No PoC code was found to be publicly available at the time of this research. SecurityWeek additionally notes the same Patch Day carried 8 high-severity notes spanning ABAP Developer Tools, Commerce Cloud, Change and Transport System, BusinessObjects, and the Business AI Platform (Approuter) component, indicating a broad patch scope beyond the four critical CVEs documented here.
Weaknesses (CWE)
CWE-94, CWE-787
Timeline
- CVE-2026-34265 (SAP AS ABAP DIAG protocol memory corruption) is reserved in the CVE registry.
- CVE-2026-44758 (SAP MII code injection) is reserved in the CVE registry.
- CVE-2026-58231 (SAP Commerce Cloud Data Hub Adapter improper authorization) is reserved in the CVE registry.
- CISA's Known Exploited Vulnerabilities catalog (version 2026.08.10, 1,662 entries) is released without any of the four SAP CVEs listed.
- NVD publishes CVE-2026-34265 (CVSS 9.8, SAP AS ABAP DIAG protocol memory corruption), one day ahead of SAP's coordinated Patch Day announcement.
- NVD publishes CVE-2026-44758 (CVSS 9.1, SAP MII code injection), one day ahead of SAP's coordinated Patch Day announcement.
- SAP's August 2026 Security Patch Day releases 28 new security notes, 2 updates, and 1 GitHub security advisory, including 4 critical and 8 high-severity notes.
- CVE-2026-58231 (CVSS 10.0) is publicly disclosed and published in NVD alongside SAP Security Note 3771065.
- CVE-2026-44772 (CVSS 9.9) is publicly disclosed in the MII component; still RESERVED-only with no NVD or CVE.org record confirmed at time of research.
- SecurityWeek and other outlets publish coverage of the August 2026 SAP Security Patch Day, noting no reported in-the-wild exploitation of any of the four critical CVEs.
- NVD last-modified the CVE-2026-58231 record.
- The Hacker News and PCQuest published initial technical coverage of CVE-2026-58231, describing the default-authentication-client abuse and unauthenticated arbitrary code execution path.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 27 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
VULNERABILITY, CRITICAL, threat intelligence, cybersecurity, CVE-2026-58231, CVE-2026-44772, CVE-2026-44758, CVE-2026-34265, T1190, T1078.001, T1078, T1059, T1211, T1082, T1005, T1499.004, T1595.002, T1213