Skip to content

SAP Security Patch Day – August 2026

Gert Jan
Gert-Jan Koster
SAP Security specialist
August 11, 2026
9 min read

Chapters

Share Article

Let's Talk SAP Security

Have questions about SAP Security? We’re here to help. Contact Us

Text Base Post Tile

SAP security should remain a key priority, and this month’s Patch Day reinforces exactly why. With 26 new Security Notes released in August, the volume is significant and once again highlights the risks associated with delaying security updates. Many successful attacks still exploit vulnerabilities for which patches are already available. Applying security patches as quickly as possible remains one of the most effective ways to reduce exposure to known vulnerabilities and limit the attack surface across SAP landscapes.

This month’s SAP Security Patch Day includes 26 new Security Notes released today, together with 3 updates issued between patch days. Each of these should be carefully assessed and prioritized based on its relevance and potential impact. Below, we highlight the most important Security Notes from August and explain what they could mean for your SAP landscape.

SAP environments are becoming increasingly complex, often combining on-premise systems, cloud services, and hybrid architectures. This makes patch management much more than a standard maintenance task. With many interconnected components and dependencies, patching can become difficult to plan, resource-intensive, and time-consuming. Increasing the risk that important fixes are overlooked. At SecurityBridge, we recognize these challenges.

The SecurityBridge Patch Management for SAP solution helps organizations identify missing patches across their SAP landscape, offering clear visibility, impact analysis, and automated implementation support. By providing a system-wide overview, it helps accelerate patching cycles and strengthen continuous threat monitoring, contributing to a more secure and resilient SAP environment throughout 2026.

SecurityBridge Findings!

At SecurityBridge, we don’t just provide a comprehensive SAP security platform we are also deeply committed to ongoing research within the SAP security domain.

For this month’s release, our latest discoveries include

  • Low priority: note 3763028 – [CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)

SAP Manufacturing Integration and Intelligence in the spotlight

For this month’s patch cycle, we see six notes related to SAP Manufacturing Integration and Intelligence (SAP MII). SAP MII is a manufacturing integration solution that connects shop-floor systems and equipment to enterprise systems (such as SAP ERP or SAP S/4 HANA). Technically, it is deployed on SAP NetWeaver Java. This month’s notes include:

SAP MII is certainly not used by every SAP customer,  but if you have SAP MII in your landscape, take special care this month to make sure you’re up to date!

 

HotNews

Let’s start with HotNews, the highest-priority category. This month, we have 4 notes to consider in this category. 

3765948 – Code Injection vulnerability in SAP Manufacturing Integration and Intelligence

In SAP Manufacturing Integration and Intelligence (MII), a vulnerability exists in XSL transformation which can lead to execution of arbitrary commands. After the patch is applied, system properties need to be maintained. There is no workaround. See FAQ note 3789518 for additional information.

3747367 – Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP

This note was initially released as part of July’s Patch Tuesday and has been updated with updated correction information. Kernel 7.89 is now a part of the correction as well. Make sure to check whether this update is relevant for your landscape. 

3714806 – Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform

The DIAG protocol of the ABAP technology stack has been found to be vulnerable to memory corruption, potentially resulting in a significant impact on the application. This requires a kernel patch, which may have an impact on system availability. See FAQ note 3746868 for additional information.

3758900 – Code Injection vulnerability in Manufacturing Integration and Intelligence

This vulnerability also affects SAP MII and relates to the same area as note 3765948. The servlet used for XSL transformation does not properly validate supplied input, leading to the potential execution of arbitrary commands on the underlying system. There is a workaround, but, as always, the patch is strongly recommended. See FAQ document 3775178 for additional information.

 

High-Priority Notes

Next up is the High Priority category, with nine notes to consider this month. See the highlights below.

3772411 – Privilege Escalation vulnerability in SAP ABAP Developer Tools

The ABAP Developer Tools lack authorization checks for the SQL Console when using host expressions, which can lead to severe impact on the application. A workaround is possible using authorization objects S_TABU_NAM and S_TABU_DIS. See FAQ note 3790544 for additional information.

3773203 – Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX

Almost every month, patches are released to address vulnerabilities in underlying libraries. This time, the issue concerns a vulnerable version of NGINX used by SAP Commerce Cloud. The updated version can be retrieved by customers and deployed to affected environments.

3786038 – Multiple vulnerabilities in SAP Business AI Platform (Approuter)

This note addresses multiple vulnerabilities in the Approuter component. The Approuter is a Node.js-based component used for various communication functions and is often deployed in SAP BTP environments. The highest CVSS score is 7.0. To fix these vulnerabilities, update to package 23.0.0 or higher. Interestingly: this version is not released yet… 

Note that the XSUAA redirect URIs need to be configured properly before updating the package.

 

Medium- and Low-Priority Notes

As we see in almost every patch cycle, the majority of security notes fall into the Medium or Low category. This time, there are fourteen and two respectively. These issues can typically be resolved by simply applying the supplied patches. We highlight additional key findings below, and for a full breakdown, please scroll to the end of this post.

3721424 – Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP

This XSS vulnerability concerns the Unified Rendering (UR) framework on ABAP systems. For further details on the implementation of Unified Rendering corrections, see notes 2504011 (SAP GUI for HTML) and 2090746 (Web Dynpro ABAP).

3772071 – Cross Site Scripting (XSS) vulnerability in SAPUI5

This XSS vulnerability concerns SAPUI5 and requires the component to be patched on affected ABAP systems. See note 3155948 for additional information on patching SAPUI5 for ABAP.

 

SAP Security Notes August 2026

Highlights

A relatively large number of notes overall, with SAP Manufacturing Integration and Intelligence in the spotlight.

Summary by Severity

The August release contains a total of 29 patches (including in-between patches) for the following severities:

   
       
                   

               

         
     
 
SeverityNumber
Hot News
4
High
9
Medium
14
Low
2
       
   
NoteDescriptionSeverityCVSS
3747367[CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
Priority: HotNews
Released on: 7/14/26
Components: BC-FES-ITS
Category: Program error
Hot News9.9
3765948[CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence
Priority: HotNews
Released on: 8/11/26
Components: MFG-MII
Category: Program error
Hot News9.9
3714806[CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Priority: HotNews
Released on: 8/11/26
Components: BC-ABA-SC
Category: Program error
Hot News9.8
3758900[CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence
Priority: HotNews
Released on: 8/11/26
Components: MFG-MII
Category: Program error
Hot News9.1
3772411[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools
Priority: Correction with high priority
Released on: 8/11/26
Components: BC-DWB-AIE-DP
Category: Program error
High8.8
3732471[CVE-2026-34259] OS Command Injection Vulnerability in SAP Forecasting & Replenishment
Priority: Correction with high priority
Released on: 5/12/26
Components: SCM-FRE-FRP
Category: Program error
High8.2
3773203[CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX
Priority: Correction with high priority
Released on: 8/11/26
Components: CEC-SCC-CLA-ENV-EMG
Category: Program error
High8.1
3756565[CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Priority: Correction with high priority
Released on: 8/11/26
Components: BI-BIP-SRV
Category: Program error
High7.9
3759854[CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence
Priority: Correction with high priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
High7.6
3773304[CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)
Priority: Correction with high priority
Released on: 7/14/26
Components: BC-CTS-TMS-PLS
Category: Program error
High7.6
3758657[CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Priority: Correction with high priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
High7.3
3758910[CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Priority: Correction with high priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
High7.3
3786038[CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Priority: Correction with high priority
Released on: 8/11/26
Components: BC-XS-APR
Category: Program error
High7.0
3753141[CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence
Priority: Correction with medium priority
Released on: 8/11/26
Components: BI-RA-WBI
Category: Program error
Medium6.5
3766473[CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence
Priority: Correction with medium priority
Released on: 8/11/26
Components: CA-EPT-SMI
Category: Program error
Medium6.3
3721424[CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-WD-UR
Category: Program error
Medium6.3
3758318[CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-SRV-FP
Category: Program error
Medium6.3
3772071[CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5
Priority: Correction with medium priority
Released on: 8/11/26
Components: CA-UI5-COR
Category: Program error
Medium6.1
3745182[CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CST-DP
Category: Program error
Medium5.5
3540688[CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework
Priority: Correction with medium priority
Released on: 7/22/25
Components: FI-LOC-CA-XX
Category: Program error
Medium5.5
3756674[CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CST-DP
Category: Program error
Medium5.3
3725940[CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CCM-PRN
Category: Program error
Medium5.3
3770649[CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)
Priority: Correction with medium priority
Released on: 8/11/26
Components: BI-BIP-INV
Category: Program error
Medium4.3
3781137[CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)
Priority: Correction with medium priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
Medium4.3
3413033[CVE-2026-58246 ] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Priority: Correction with medium priority
Released on: 7/28/26
Components: BC-MID-ICF
Category: Program error
Medium4.3
3669608[CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
Priority: Correction with medium priority
Released on: 11/19/25
Components: FI-FIO-AR-PAY
Category: Program error
Medium4.3
3752864[CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CTS-TMS-CTR
Category: Program error
Medium4.2
3763028[CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
Priority: Correction with low priority
Released on: 8/11/26
Components: SCM-APO-PPS-MMP
Category: Program error
Low3.8
3739913[CVE-2026-44762 ] Security Misconfiguration in SAP Data Services Management Console
Priority: Correction with low priority
Released on: 8/11/26
Components: EIM-DS-DEP
Category: Program error
Low3.7