SAP Security Patch Day – August 2026
Chapters
Share Article
Let's Talk SAP Security
Have questions about SAP Security? We’re here to help. Contact Us
SAP security should remain a key priority, and this month’s Patch Day reinforces exactly why. With 26 new Security Notes released in August, the volume is significant and once again highlights the risks associated with delaying security updates. Many successful attacks still exploit vulnerabilities for which patches are already available. Applying security patches as quickly as possible remains one of the most effective ways to reduce exposure to known vulnerabilities and limit the attack surface across SAP landscapes.
This month’s SAP Security Patch Day includes 26 new Security Notes released today, together with 3 updates issued between patch days. Each of these should be carefully assessed and prioritized based on its relevance and potential impact. Below, we highlight the most important Security Notes from August and explain what they could mean for your SAP landscape.
SAP environments are becoming increasingly complex, often combining on-premise systems, cloud services, and hybrid architectures. This makes patch management much more than a standard maintenance task. With many interconnected components and dependencies, patching can become difficult to plan, resource-intensive, and time-consuming. Increasing the risk that important fixes are overlooked. At SecurityBridge, we recognize these challenges.
The SecurityBridge Patch Management for SAP solution helps organizations identify missing patches across their SAP landscape, offering clear visibility, impact analysis, and automated implementation support. By providing a system-wide overview, it helps accelerate patching cycles and strengthen continuous threat monitoring, contributing to a more secure and resilient SAP environment throughout 2026.
SecurityBridge Findings!
At SecurityBridge, we don’t just provide a comprehensive SAP security platform we are also deeply committed to ongoing research within the SAP security domain.
For this month’s release, our latest discoveries include
- Low priority: note 3763028 – [CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
SAP Manufacturing Integration and Intelligence in the spotlight
For this month’s patch cycle, we see six notes related to SAP Manufacturing Integration and Intelligence (SAP MII). SAP MII is a manufacturing integration solution that connects shop-floor systems and equipment to enterprise systems (such as SAP ERP or SAP S/4 HANA). Technically, it is deployed on SAP NetWeaver Java. This month’s notes include:
- HotNews: Notes 3765948 and 3758900
- High priority: Notes 3759854, 3758657 and 3758910
- Medium priority: Note 3781137
SAP MII is certainly not used by every SAP customer, but if you have SAP MII in your landscape, take special care this month to make sure you’re up to date!
HotNews
Let’s start with HotNews, the highest-priority category. This month, we have 4 notes to consider in this category.
3765948 – Code Injection vulnerability in SAP Manufacturing Integration and Intelligence
In SAP Manufacturing Integration and Intelligence (MII), a vulnerability exists in XSL transformation which can lead to execution of arbitrary commands. After the patch is applied, system properties need to be maintained. There is no workaround. See FAQ note 3789518 for additional information.
3747367 – Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
This note was initially released as part of July’s Patch Tuesday and has been updated with updated correction information. Kernel 7.89 is now a part of the correction as well. Make sure to check whether this update is relevant for your landscape.
3714806 – Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
The DIAG protocol of the ABAP technology stack has been found to be vulnerable to memory corruption, potentially resulting in a significant impact on the application. This requires a kernel patch, which may have an impact on system availability. See FAQ note 3746868 for additional information.
3758900 – Code Injection vulnerability in Manufacturing Integration and Intelligence
This vulnerability also affects SAP MII and relates to the same area as note 3765948. The servlet used for XSL transformation does not properly validate supplied input, leading to the potential execution of arbitrary commands on the underlying system. There is a workaround, but, as always, the patch is strongly recommended. See FAQ document 3775178 for additional information.
High-Priority Notes
Next up is the High Priority category, with nine notes to consider this month. See the highlights below.
3772411 – Privilege Escalation vulnerability in SAP ABAP Developer Tools
The ABAP Developer Tools lack authorization checks for the SQL Console when using host expressions, which can lead to severe impact on the application. A workaround is possible using authorization objects S_TABU_NAM and S_TABU_DIS. See FAQ note 3790544 for additional information.
3773203 – Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX
Almost every month, patches are released to address vulnerabilities in underlying libraries. This time, the issue concerns a vulnerable version of NGINX used by SAP Commerce Cloud. The updated version can be retrieved by customers and deployed to affected environments.
3786038 – Multiple vulnerabilities in SAP Business AI Platform (Approuter)
This note addresses multiple vulnerabilities in the Approuter component. The Approuter is a Node.js-based component used for various communication functions and is often deployed in SAP BTP environments. The highest CVSS score is 7.0. To fix these vulnerabilities, update to package 23.0.0 or higher. Interestingly: this version is not released yet…
Note that the XSUAA redirect URIs need to be configured properly before updating the package.
Medium- and Low-Priority Notes
As we see in almost every patch cycle, the majority of security notes fall into the Medium or Low category. This time, there are fourteen and two respectively. These issues can typically be resolved by simply applying the supplied patches. We highlight additional key findings below, and for a full breakdown, please scroll to the end of this post.
3721424 – Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
This XSS vulnerability concerns the Unified Rendering (UR) framework on ABAP systems. For further details on the implementation of Unified Rendering corrections, see notes 2504011 (SAP GUI for HTML) and 2090746 (Web Dynpro ABAP).
3772071 – Cross Site Scripting (XSS) vulnerability in SAPUI5
This XSS vulnerability concerns SAPUI5 and requires the component to be patched on affected ABAP systems. See note 3155948 for additional information on patching SAPUI5 for ABAP.
SAP Security Notes August 2026
Highlights
A relatively large number of notes overall, with SAP Manufacturing Integration and Intelligence in the spotlight.
Summary by Severity
The August release contains a total of 29 patches (including in-between patches) for the following severities:
| Severity | Number | Hot News | 4 |
|---|---|
High | 9 |
Medium | 14 |
Low | 2 |
| Note | Description | Severity | CVSS |
|---|---|---|---|
| 3747367 | [CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP Priority: HotNews Released on: 7/14/26 Components: BC-FES-ITS Category: Program error | Hot News | 9.9 |
| 3765948 | [CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence Priority: HotNews Released on: 8/11/26 Components: MFG-MII Category: Program error | Hot News | 9.9 |
| 3714806 | [CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform Priority: HotNews Released on: 8/11/26 Components: BC-ABA-SC Category: Program error | Hot News | 9.8 |
| 3758900 | [CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence Priority: HotNews Released on: 8/11/26 Components: MFG-MII Category: Program error | Hot News | 9.1 |
| 3772411 | [CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools Priority: Correction with high priority Released on: 8/11/26 Components: BC-DWB-AIE-DP Category: Program error | High | 8.8 |
| 3732471 | [CVE-2026-34259] OS Command Injection Vulnerability in SAP Forecasting & Replenishment Priority: Correction with high priority Released on: 5/12/26 Components: SCM-FRE-FRP Category: Program error | High | 8.2 |
| 3773203 | [CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX Priority: Correction with high priority Released on: 8/11/26 Components: CEC-SCC-CLA-ENV-EMG Category: Program error | High | 8.1 |
| 3756565 | [CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) Priority: Correction with high priority Released on: 8/11/26 Components: BI-BIP-SRV Category: Program error | High | 7.9 |
| 3759854 | [CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence Priority: Correction with high priority Released on: 8/11/26 Components: MFG-MII Category: Program error | High | 7.6 |
| 3773304 | [CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach) Priority: Correction with high priority Released on: 7/14/26 Components: BC-CTS-TMS-PLS Category: Program error | High | 7.6 |
| 3758657 | [CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Priority: Correction with high priority Released on: 8/11/26 Components: MFG-MII Category: Program error | High | 7.3 |
| 3758910 | [CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Priority: Correction with high priority Released on: 8/11/26 Components: MFG-MII Category: Program error | High | 7.3 |
| 3786038 | [CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter) Priority: Correction with high priority Released on: 8/11/26 Components: BC-XS-APR Category: Program error | High | 7.0 |
| 3753141 | [CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence Priority: Correction with medium priority Released on: 8/11/26 Components: BI-RA-WBI Category: Program error | Medium | 6.5 |
| 3766473 | [CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence Priority: Correction with medium priority Released on: 8/11/26 Components: CA-EPT-SMI Category: Program error | Medium | 6.3 |
| 3721424 | [CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP Priority: Correction with medium priority Released on: 8/11/26 Components: BC-WD-UR Category: Program error | Medium | 6.3 |
| 3758318 | [CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) Priority: Correction with medium priority Released on: 8/11/26 Components: BC-SRV-FP Category: Program error | Medium | 6.3 |
| 3772071 | [CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5 Priority: Correction with medium priority Released on: 8/11/26 Components: CA-UI5-COR Category: Program error | Medium | 6.1 |
| 3745182 | [CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CST-DP Category: Program error | Medium | 5.5 |
| 3540688 | [CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework Priority: Correction with medium priority Released on: 7/22/25 Components: FI-LOC-CA-XX Category: Program error | Medium | 5.5 |
| 3756674 | [CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CST-DP Category: Program error | Medium | 5.3 |
| 3725940 | [CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CCM-PRN Category: Program error | Medium | 5.3 |
| 3770649 | [CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools) Priority: Correction with medium priority Released on: 8/11/26 Components: BI-BIP-INV Category: Program error | Medium | 4.3 |
| 3781137 | [CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII) Priority: Correction with medium priority Released on: 8/11/26 Components: MFG-MII Category: Program error | Medium | 4.3 |
| 3413033 | [CVE-2026-58246 ] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform Priority: Correction with medium priority Released on: 7/28/26 Components: BC-MID-ICF Category: Program error | Medium | 4.3 |
| 3669608 | [CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items) Priority: Correction with medium priority Released on: 11/19/25 Components: FI-FIO-AR-PAY Category: Program error | Medium | 4.3 |
| 3752864 | [CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CTS-TMS-CTR Category: Program error | Medium | 4.2 |
| 3763028 | [CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning) Priority: Correction with low priority Released on: 8/11/26 Components: SCM-APO-PPS-MMP Category: Program error | Low | 3.8 |
| 3739913 | [CVE-2026-44762 ] Security Misconfiguration in SAP Data Services Management Console Priority: Correction with low priority Released on: 8/11/26 Components: EIM-DS-DEP Category: Program error | Low | 3.7 |
