SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)
SAP Patches Critical Code Injection, Memory Corruption (TL-2026-1984) is a critical-severity software vulnerability scored CVSS 10, first published 2026-08-11 and last reviewed 2026-08-16. It has no confirmed attribution, affects SAP SAP Commerce Cloud (Data Hub Adapter), references 4 CVEs (CVE-2026-58231, CVE-2026-44772, CVE-2026-44758), maps to 17 MITRE ATT&CK techniques (T1005, T1059, T1068), and is covered by 9 detection rules and 27 indicators of compromise.
Key facts for TL-2026-1984
- Threat ID
- TL-2026-1984
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- 2026-08-11
- Last reviewed
- 2026-08-16
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Detection rules
- 9
- Indicators of compromise
- 27
- Updates
- 2026-08-16 · 3 updates · revalidated 3× · latest source
SAP's August 11, 2026 Security Patch Day shipped 28 new security notes, 2 updates, and 1 GitHub security advisory, including four critical-severity fixes. CVE-2026-58231 (CVSS 10.0) is an improper-authorization/code-injection flaw in SAP Commerce Cloud's Data Hub Adapter that lets an unauthenticated attacker abuse a default authentication client to reach unvalidated functions and internal components, likely achieving code execution. CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1) are code-injection flaws in Manufacturing Integration and Intelligence (MII) that let a high-privileged attacker submit crafted input to run arbitrary OS commands on the host. CVE-2026-34265 (CVSS 9.8) is an unauthenticated memory-corruption bug in NetWeaver/ABAP Platform's Application Server ABAP, rooted in DIAG protocol parsing, that can disclose sensitive data or crash the system.
How SAP Patches Critical Code Injection, Memory Corruption works
On August 11, 2026, SAP's monthly Security Patch Day released 28 new security notes, 2 updates to prior notes, and 1 GitHub security advisory. Four of the new notes are rated critical.
The most severe, CVE-2026-58231 (CVSS v3.1: 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-94 Improper Control of Generation of Code / Code Injection, per NVD's published record), affects the Data Hub Adapter component of SAP Commerce Cloud (COM_CLOUD 2211 and 2211-JDK21). An unauthenticated remote attacker can abuse a default authentication client and submit specially crafted input to functions that lack sufficient validation, bypassing authorization to reach internal components and likely execute arbitrary code. SAP published the fix as Security Note 3771065; NVD lists the publication date as August 11, 2026.
CVE-2026-34265 (CVSS v3.1: 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-787 Out-of-bounds Write) is a memory-corruption vulnerability in SAP NetWeaver/ABAP Platform's Application Server ABAP, caused by logical errors in DIAG protocol parsing. It is exploitable by an unauthenticated network attacker and can disclose sensitive system information or crash the affected process. NVD's confirmed affected build list is: KRNL64NUC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, and KERNEL/ABAP Platform builds 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, and 9.19; the fix is documented in SAP Security Note 3714806. NVD's publication timestamp for this record (August 10, 2026) is one day ahead of SAP's coordinated August 11 Patch Day announcement, a UTC-boundary artifact seen across SAP's monthly disclosures.
CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS v3.1: 9.1, AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, CWE-94) are code-injection flaws in SAP Manufacturing Integration and Intelligence (MII; affected as XMII 15.4/15.5 for CVE-2026-44758). Both require an attacker to already hold elevated ('high') privileges within the application; SecurityWeek's analysis further distinguishes that CVE-2026-44772 needs only 'standard' privileges while CVE-2026-44758 requires a higher privilege level, consistent with the PR:H CVSS component on -44758. In both cases, vulnerable servlets process crafted input without sufficient validation, resulting in execution of arbitrary commands on the underlying host OS. The CVSS Scope-Changed (S:C) rating on CVE-2026-44758 reflects that impact extends beyond the vulnerable MII component to the host OS. SAP's fix for CVE-2026-44758 is documented in Security Note 3758900 (NVD publication timestamp August 10, 2026); CVE-2026-44772 remains a RESERVED-only CVE ID with no published NVD record at time of research (confirmed via direct NVD and CVE.org lookups), so only the vendor/press-reported CVSS and vulnerability class are confirmed.
SAP made no mention of in-the-wild exploitation for any of the four CVEs, and as of the CISA KEV catalog's August 10, 2026 release (catalog version 2026.08.10, 1,662 entries, confirmed by direct fetch), none of the four are listed as known-exploited. No PoC code was found to be publicly available at the time of this research. SecurityWeek additionally notes the same Patch Day carried 8 high-severity notes spanning ABAP Developer Tools, Commerce Cloud, Change and Transport System, BusinessObjects, and the Business AI Platform (Approuter) component, indicating a broad patch scope beyond the four critical CVEs documented here.
MITRE ATT&CK techniques used in TL-2026-1984
Collection
T1005 Data from Local System; T1213 Data from Information Repositories
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Persistence
Initial Access
T1078.001 Default Accounts; T1190 Exploit Public-Facing Application
Discovery
T1082 System Information Discovery
Lateral Movement
T1210 Exploitation of Remote Services
Stealth
T1211 Exploitation for Stealth
Impact
T1499.004 Application or System Exploitation; T1565.001 Data Manipulation
Resource Development
T1583.004 Acquire Infrastructure: Server; T1587.004 Develop Capabilities: Exploits; T1588.006 Obtain Capabilities: Vulnerabilities
Reconnaissance
Affected products and versions in SAP Patches Critical Code Injection, Memory Corruption
- SAP — SAP Commerce Cloud (Data Hub Adapter)
Vulnerable versions: COM_CLOUD 2211; COM_CLOUD 2211-JDK21
Fixed in: Patched per SAP Security Note 3771065 - SAP — SAP NetWeaver / ABAP Platform, Application Server ABAP
Vulnerable versions: KRNL64NUC 7.22; KRNL64NUC 7.22EXT; KRNL64NUC 7.22EXT2; KRNL64NUC 7.22EXT3; KERNEL 7.53; KERNEL 7.54; KERNEL 7.77; KERNEL 7.89; KERNEL 7.93; KERNEL 8.04
Fixed in: Patched per SAP Security Note 3714806 - SAP — SAP Manufacturing Integration and Intelligence (MII)
Vulnerable versions: XMII 15.4; XMII 15.5
Fixed in: Patched per SAP Security Note 3758900 (CVE-2026-44758) and the corresponding August 2026 note for CVE-2026-44772
Remediation for SAP Patches Critical Code Injection, Memory Corruption
Patches
- SAP Security Note 3771065 (CVE-2026-58231, SAP Commerce Cloud Data Hub Adapter)
- SAP Security Note 3714806 (CVE-2026-34265, NetWeaver/ABAP Platform Application Server ABAP)
- SAP Security Note 3758900 (CVE-2026-44758, SAP Manufacturing Integration and Intelligence)
- August 2026 SAP Security Patch Day note for CVE-2026-44772 (SAP Manufacturing Integration and Intelligence)
Immediate actions
- Apply SAP Security Note 3771065 to remediate CVE-2026-58231 in the Commerce Cloud Data Hub Adapter (COM_CLOUD 2211 / 2211-JDK21)
- Apply SAP Security Note 3714806 to remediate CVE-2026-34265 in NetWeaver/ABAP Platform Application Server ABAP (KRNL64NUC/KERNEL builds 7.22-7.93, 8.04, 9.16-9.19)
- Apply SAP Security Note 3758900 to remediate CVE-2026-44758 in Manufacturing Integration and Intelligence (XMII 15.4/15.5)
- Locate and apply the August 2026 Patch Day security note covering CVE-2026-44772 in Manufacturing Integration and Intelligence
- Rotate or disable any default/standard authentication client credentials configured on the Commerce Cloud Data Hub Adapter
Workarounds
- Until patched, block or firewall external/untrusted access to the SAP NetWeaver AS ABAP dispatcher (DIAG) port and the Commerce Cloud Data Hub Adapter endpoint
Longer-term hardening
- Restrict network exposure of the AS ABAP dispatcher (DIAG protocol) and the Commerce Cloud Data Hub Adapter servlet to trusted management networks only
- Tie SAP patch management to the monthly SAP Security Patch Day cadence and track KERNEL/component patch levels against SAP Security Notes 3771065, 3714806, and 3758900
- Restrict MII (XMII) administrative/high-privilege roles to the minimum set of accounts that require them, given both MII CVEs require an already-privileged attacker
- Enable and review SAP Security Audit Log and ICM/Web Dispatcher access logging for Data Hub Adapter and DIAG traffic
CVEs associated with SAP Patches Critical Code Injection, Memory Corruption
CVE-2026-58231, CVE-2026-44772, CVE-2026-44758, CVE-2026-34265
Weaknesses (CWE) in SAP Patches Critical Code Injection, Memory Corruption
CWE-94, CWE-787
Timeline of SAP Patches Critical Code Injection, Memory Corruption
- CVE-2026-34265 (SAP AS ABAP DIAG protocol memory corruption) is reserved in the CVE registry.
- CVE-2026-44758 (SAP MII code injection) is reserved in the CVE registry.
- CVE-2026-58231 (SAP Commerce Cloud Data Hub Adapter improper authorization) is reserved in the CVE registry.
- NVD publishes CVE-2026-44758 (CVSS 9.1, SAP MII code injection), one day ahead of SAP's coordinated Patch Day announcement.
- NVD publishes CVE-2026-34265 (CVSS 9.8, SAP AS ABAP DIAG protocol memory corruption), one day ahead of SAP's coordinated Patch Day announcement.
- CISA's Known Exploited Vulnerabilities catalog (version 2026.08.10, 1,662 entries) is released without any of the four SAP CVEs listed.
- SecurityWeek and other outlets publish coverage of the August 2026 SAP Security Patch Day, noting no reported in-the-wild exploitation of any of the four critical CVEs.
- CVE-2026-44772 (CVSS 9.9) is publicly disclosed in the MII component; still RESERVED-only with no NVD or CVE.org record confirmed at time of research.
- CVE-2026-58231 (CVSS 10.0) is publicly disclosed and published in NVD alongside SAP Security Note 3771065.
- SAP's August 2026 Security Patch Day releases 28 new security notes, 2 updates, and 1 GitHub security advisory, including 4 critical and 8 high-severity notes.
- The Hacker News and PCQuest published initial technical coverage of CVE-2026-58231, describing the default-authentication-client abuse and unauthenticated arbitrary code execution path.
- NVD last-modified the CVE-2026-58231 record.
- Defused shares a link to a captured CVE-2026-58231 exploitation payload sample via a post on X.
- SAP security specialist Onapsis urged affected customers to patch to fixed releases (2211.55 / 2211-jdk21.17) and redeploy, recommending an IP Filter Set on the Data Hub Adapter import endpoint as an interim workaround; SAP stated it was investigating the reported exploitation activity.
- Threat intelligence analysis classified the honeypot-observed traffic as automated mass scanning of internet-facing SAP deployments, assessing that attackers had reverse-engineered the vendor patch given the absence of any public proof-of-concept.
- The Shadowserver Foundation reports over 4,200 internet-exposed SAP Commerce Cloud instances fingerprinted, concentrated in Europe and North America.
- Threat-intel firm Defused detects the first in-the-wild exploitation attempts against CVE-2026-58231 hitting its honeypots, roughly three days after patch release, with no public PoC known to exist.
- Cyber Security News, BleepingComputer, The Hacker News, eSecurity Planet, Field Effect, SOCRadar, and other outlets published reports on active in-the-wild exploitation of CVE-2026-58231, with defenders advised to inspect WAF/ingress logs for anomalous administrative-endpoint POST requests.
Update history for TL-2026-1984
- 2026-08-16 — SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) — Unauthenticated RCE in Data Hub Adapter Exploited Days After Patch: What changed No severity/exploitability escalation — already CRITICAL / ACTIVE / CVSS 10.0 in the existing record. The newer report adds downstream-impact analysis (ERP/CRM/inventory/payment-processing exposure reachable via the Data Hub Ad
- 2026-08-15 — Active Exploitation of Critical SAP Commerce Cloud RCE (CVE-2026-58231) Within Days of Patch: What changed No field escalation needed — severity (CRITICAL), exploitability (ACTIVE), and status (ACTIVE) were already set on the existing record from the prior revalidation. This report corroborates active exploitation and adds indicator
- 2026-08-15 — CVE-2026-58231: Maximum-Severity Unauthenticated RCE in SAP Commerce Cloud Data Hub Adapter Actively Exploited: What changed Exploitability escalated THEORETICAL → ACTIVE: Defused detected in-the-wild honeypot exploitation of CVE-2026-58231 roughly three days after SAP's August 11 patch, and Shadowserver counted 4,200+ internet-exposed SAP Commerce C
Sources cited for SAP Patches Critical Code Injection, Memory Corruption
- SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
- SAP Security Patch Day - August 2026
- SAP Security Note 3771065 (CVE-2026-58231)
- SAP Security Note 3714806 (CVE-2026-34265)
- SAP Security Note 3758900 (CVE-2026-44758)
- NVD Detail - CVE-2026-58231
- NVD Detail - CVE-2026-34265
- NVD Detail - CVE-2026-44758
- NVD Detail - CVE-2026-44772 (RESERVED, no published record)
- CISA Known Exploited Vulnerabilities Catalog v2026.08.10 (four CVEs absent)
- CVE-2026-58231 Technical Detail
- Live Cybersecurity Brief for August 11, 2026
Threats related to SAP Patches Critical Code Injection, Memory Corruption
- Progress ShareFile Zero-Day Path Traversal Flaw Forces Storage Zone Controller Shutdown
- Oracle August 2026 CSPU: Nine Vulnerabilities in Agile Engineering Data Management 6.2.1, Including Unauthenticated Web Services Security Flaws (CVE-2026-71052, CVE-2026-71053)
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public Projects
- SAP Patches Critical NetWeaver, Approuter, and Commerce Cloud Flaws (CVE-2026-44747, CVE-2026-27690, CVE-2026-44761)
- Google Chrome 151 Update Fixes 41 Security Vulnerabilities, Including 6 Critical Flaws
- SCTPhantom (CVE-2026-64564): 18-Year-Old Use-After-Free in Linux Kernel SCTP ASCONF Handling Enables Local Privilege Escalation
Detection coverage for TL-2026-1984
As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1984 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.