SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities (CVE-2026-58231, CVSS 10.0)

SAP Patches Critical Code Injection, Memory Corruption (TL-2026-1984) is a critical-severity software vulnerability scored CVSS 10, first published 2026-08-11 and last reviewed 2026-08-16. It has no confirmed attribution, affects SAP SAP Commerce Cloud (Data Hub Adapter), references 4 CVEs (CVE-2026-58231, CVE-2026-44772, CVE-2026-44758), maps to 17 MITRE ATT&CK techniques (T1005, T1059, T1068), and is covered by 9 detection rules and 27 indicators of compromise.

Key facts for TL-2026-1984

Threat ID
TL-2026-1984
Severity
CRITICAL
CVSS
10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
Status
ACTIVE
Category
VULNERABILITY
First published
2026-08-11
Last reviewed
2026-08-16
Attribution confidence
LOW
Motivation
UNKNOWN
Detection rules
9
Indicators of compromise
27
Updates
2026-08-16 · 3 updates · revalidated 3× · latest source

SAP's August 11, 2026 Security Patch Day shipped 28 new security notes, 2 updates, and 1 GitHub security advisory, including four critical-severity fixes. CVE-2026-58231 (CVSS 10.0) is an improper-authorization/code-injection flaw in SAP Commerce Cloud's Data Hub Adapter that lets an unauthenticated attacker abuse a default authentication client to reach unvalidated functions and internal components, likely achieving code execution. CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1) are code-injection flaws in Manufacturing Integration and Intelligence (MII) that let a high-privileged attacker submit crafted input to run arbitrary OS commands on the host. CVE-2026-34265 (CVSS 9.8) is an unauthenticated memory-corruption bug in NetWeaver/ABAP Platform's Application Server ABAP, rooted in DIAG protocol parsing, that can disclose sensitive data or crash the system.

How SAP Patches Critical Code Injection, Memory Corruption works

On August 11, 2026, SAP's monthly Security Patch Day released 28 new security notes, 2 updates to prior notes, and 1 GitHub security advisory. Four of the new notes are rated critical.

The most severe, CVE-2026-58231 (CVSS v3.1: 10.0, AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, CWE-94 Improper Control of Generation of Code / Code Injection, per NVD's published record), affects the Data Hub Adapter component of SAP Commerce Cloud (COM_CLOUD 2211 and 2211-JDK21). An unauthenticated remote attacker can abuse a default authentication client and submit specially crafted input to functions that lack sufficient validation, bypassing authorization to reach internal components and likely execute arbitrary code. SAP published the fix as Security Note 3771065; NVD lists the publication date as August 11, 2026.

CVE-2026-34265 (CVSS v3.1: 9.8, AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, CWE-787 Out-of-bounds Write) is a memory-corruption vulnerability in SAP NetWeaver/ABAP Platform's Application Server ABAP, caused by logical errors in DIAG protocol parsing. It is exploitable by an unauthenticated network attacker and can disclose sensitive system information or crash the affected process. NVD's confirmed affected build list is: KRNL64NUC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, and KERNEL/ABAP Platform builds 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, and 9.19; the fix is documented in SAP Security Note 3714806. NVD's publication timestamp for this record (August 10, 2026) is one day ahead of SAP's coordinated August 11 Patch Day announcement, a UTC-boundary artifact seen across SAP's monthly disclosures.

CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS v3.1: 9.1, AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H, CWE-94) are code-injection flaws in SAP Manufacturing Integration and Intelligence (MII; affected as XMII 15.4/15.5 for CVE-2026-44758). Both require an attacker to already hold elevated ('high') privileges within the application; SecurityWeek's analysis further distinguishes that CVE-2026-44772 needs only 'standard' privileges while CVE-2026-44758 requires a higher privilege level, consistent with the PR:H CVSS component on -44758. In both cases, vulnerable servlets process crafted input without sufficient validation, resulting in execution of arbitrary commands on the underlying host OS. The CVSS Scope-Changed (S:C) rating on CVE-2026-44758 reflects that impact extends beyond the vulnerable MII component to the host OS. SAP's fix for CVE-2026-44758 is documented in Security Note 3758900 (NVD publication timestamp August 10, 2026); CVE-2026-44772 remains a RESERVED-only CVE ID with no published NVD record at time of research (confirmed via direct NVD and CVE.org lookups), so only the vendor/press-reported CVSS and vulnerability class are confirmed.

SAP made no mention of in-the-wild exploitation for any of the four CVEs, and as of the CISA KEV catalog's August 10, 2026 release (catalog version 2026.08.10, 1,662 entries, confirmed by direct fetch), none of the four are listed as known-exploited. No PoC code was found to be publicly available at the time of this research. SecurityWeek additionally notes the same Patch Day carried 8 high-severity notes spanning ABAP Developer Tools, Commerce Cloud, Change and Transport System, BusinessObjects, and the Business AI Platform (Approuter) component, indicating a broad patch scope beyond the four critical CVEs documented here.

MITRE ATT&CK techniques used in TL-2026-1984

Collection

T1005 Data from Local System; T1213 Data from Information Repositories

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Persistence

T1078 Valid Accounts

Initial Access

T1078.001 Default Accounts; T1190 Exploit Public-Facing Application

Discovery

T1082 System Information Discovery

Lateral Movement

T1210 Exploitation of Remote Services

Stealth

T1211 Exploitation for Stealth

Impact

T1499.004 Application or System Exploitation; T1565.001 Data Manipulation

Resource Development

T1583.004 Acquire Infrastructure: Server; T1587.004 Develop Capabilities: Exploits; T1588.006 Obtain Capabilities: Vulnerabilities

Reconnaissance

T1595.001 Active Scanning; T1595.002 Active Scanning

Affected products and versions in SAP Patches Critical Code Injection, Memory Corruption

  • SAP — SAP Commerce Cloud (Data Hub Adapter)
    Vulnerable versions: COM_CLOUD 2211; COM_CLOUD 2211-JDK21
    Fixed in: Patched per SAP Security Note 3771065
  • SAP — SAP NetWeaver / ABAP Platform, Application Server ABAP
    Vulnerable versions: KRNL64NUC 7.22; KRNL64NUC 7.22EXT; KRNL64NUC 7.22EXT2; KRNL64NUC 7.22EXT3; KERNEL 7.53; KERNEL 7.54; KERNEL 7.77; KERNEL 7.89; KERNEL 7.93; KERNEL 8.04
    Fixed in: Patched per SAP Security Note 3714806
  • SAP — SAP Manufacturing Integration and Intelligence (MII)
    Vulnerable versions: XMII 15.4; XMII 15.5
    Fixed in: Patched per SAP Security Note 3758900 (CVE-2026-44758) and the corresponding August 2026 note for CVE-2026-44772

Remediation for SAP Patches Critical Code Injection, Memory Corruption

Patches

  • SAP Security Note 3771065 (CVE-2026-58231, SAP Commerce Cloud Data Hub Adapter)
  • SAP Security Note 3714806 (CVE-2026-34265, NetWeaver/ABAP Platform Application Server ABAP)
  • SAP Security Note 3758900 (CVE-2026-44758, SAP Manufacturing Integration and Intelligence)
  • August 2026 SAP Security Patch Day note for CVE-2026-44772 (SAP Manufacturing Integration and Intelligence)

Immediate actions

  • Apply SAP Security Note 3771065 to remediate CVE-2026-58231 in the Commerce Cloud Data Hub Adapter (COM_CLOUD 2211 / 2211-JDK21)
  • Apply SAP Security Note 3714806 to remediate CVE-2026-34265 in NetWeaver/ABAP Platform Application Server ABAP (KRNL64NUC/KERNEL builds 7.22-7.93, 8.04, 9.16-9.19)
  • Apply SAP Security Note 3758900 to remediate CVE-2026-44758 in Manufacturing Integration and Intelligence (XMII 15.4/15.5)
  • Locate and apply the August 2026 Patch Day security note covering CVE-2026-44772 in Manufacturing Integration and Intelligence
  • Rotate or disable any default/standard authentication client credentials configured on the Commerce Cloud Data Hub Adapter

Workarounds

  • Until patched, block or firewall external/untrusted access to the SAP NetWeaver AS ABAP dispatcher (DIAG) port and the Commerce Cloud Data Hub Adapter endpoint

Longer-term hardening

  • Restrict network exposure of the AS ABAP dispatcher (DIAG protocol) and the Commerce Cloud Data Hub Adapter servlet to trusted management networks only
  • Tie SAP patch management to the monthly SAP Security Patch Day cadence and track KERNEL/component patch levels against SAP Security Notes 3771065, 3714806, and 3758900
  • Restrict MII (XMII) administrative/high-privilege roles to the minimum set of accounts that require them, given both MII CVEs require an already-privileged attacker
  • Enable and review SAP Security Audit Log and ICM/Web Dispatcher access logging for Data Hub Adapter and DIAG traffic

CVEs associated with SAP Patches Critical Code Injection, Memory Corruption

CVE-2026-58231, CVE-2026-44772, CVE-2026-44758, CVE-2026-34265

Weaknesses (CWE) in SAP Patches Critical Code Injection, Memory Corruption

CWE-94, CWE-787

Timeline of SAP Patches Critical Code Injection, Memory Corruption

  • CVE-2026-34265 (SAP AS ABAP DIAG protocol memory corruption) is reserved in the CVE registry.
  • CVE-2026-44758 (SAP MII code injection) is reserved in the CVE registry.
  • CVE-2026-58231 (SAP Commerce Cloud Data Hub Adapter improper authorization) is reserved in the CVE registry.
  • NVD publishes CVE-2026-44758 (CVSS 9.1, SAP MII code injection), one day ahead of SAP's coordinated Patch Day announcement.
  • NVD publishes CVE-2026-34265 (CVSS 9.8, SAP AS ABAP DIAG protocol memory corruption), one day ahead of SAP's coordinated Patch Day announcement.
  • CISA's Known Exploited Vulnerabilities catalog (version 2026.08.10, 1,662 entries) is released without any of the four SAP CVEs listed.
  • SecurityWeek and other outlets publish coverage of the August 2026 SAP Security Patch Day, noting no reported in-the-wild exploitation of any of the four critical CVEs.
  • CVE-2026-44772 (CVSS 9.9) is publicly disclosed in the MII component; still RESERVED-only with no NVD or CVE.org record confirmed at time of research.
  • CVE-2026-58231 (CVSS 10.0) is publicly disclosed and published in NVD alongside SAP Security Note 3771065.
  • SAP's August 2026 Security Patch Day releases 28 new security notes, 2 updates, and 1 GitHub security advisory, including 4 critical and 8 high-severity notes.
  • The Hacker News and PCQuest published initial technical coverage of CVE-2026-58231, describing the default-authentication-client abuse and unauthenticated arbitrary code execution path.
  • NVD last-modified the CVE-2026-58231 record.
  • Defused shares a link to a captured CVE-2026-58231 exploitation payload sample via a post on X.
  • SAP security specialist Onapsis urged affected customers to patch to fixed releases (2211.55 / 2211-jdk21.17) and redeploy, recommending an IP Filter Set on the Data Hub Adapter import endpoint as an interim workaround; SAP stated it was investigating the reported exploitation activity.
  • Threat intelligence analysis classified the honeypot-observed traffic as automated mass scanning of internet-facing SAP deployments, assessing that attackers had reverse-engineered the vendor patch given the absence of any public proof-of-concept.
  • The Shadowserver Foundation reports over 4,200 internet-exposed SAP Commerce Cloud instances fingerprinted, concentrated in Europe and North America.
  • Threat-intel firm Defused detects the first in-the-wild exploitation attempts against CVE-2026-58231 hitting its honeypots, roughly three days after patch release, with no public PoC known to exist.
  • Cyber Security News, BleepingComputer, The Hacker News, eSecurity Planet, Field Effect, SOCRadar, and other outlets published reports on active in-the-wild exploitation of CVE-2026-58231, with defenders advised to inspect WAF/ingress logs for anomalous administrative-endpoint POST requests.

Update history for TL-2026-1984

Sources cited for SAP Patches Critical Code Injection, Memory Corruption

Threats related to SAP Patches Critical Code Injection, Memory Corruption

Detection coverage for TL-2026-1984

As of 2026-08-16, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1984 across Splunk SPL, Microsoft KQL and Sigma, covering 27 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats