Attackers can target SAP business software, potentially gaining full control over Commerce Cloud instances. Security updates are now available for download.
In the SAP developers’ contribution to the patch day , the software manufacturer lists 40 CVE numbers for vulnerabilities that have now been closed. Four of these vulnerabilities are classified as “ critical ”. For example, attackers can target Commerce Cloud without authentication and execute malicious code due to insufficient checks. This vulnerability (CVE-2026-58231) has the maximum CVSS score of 10 out of 10.
Manufacturing Integration and Intelligence is vulnerable via two malicious code vulnerabilities (CVE-2026-44772, CVE-2026-44758). Successful exploitation of a vulnerability (CVE-2026-34265) in Application Server ABAP for SAP NetWeaver and ABAP Platform can lead to crashes.
Furthermore, SAP developers have addressed security issues in ABAP Platform, BusinessObjects Business Intelligence, and Social Intelligence, among others. These areas can be subject to unauthorized access to sensitive data. Malicious code can also enter systems.
SAP customers can find further information on the patched versions in the support portal .
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
