Critical SAP Vulnerabilities Expose Commerce Cloud to Malicious Code Attacks

Critical SAP Vulnerabilities Expose Commerce Cloud to Malicious Code Attacks

First seen 11 Aug 2026, 21:50 UTC CybersecuritynewsHeise.De 71% similarity 75.8

Article Content

Browse articles
ThreatCluster

On August 11, 2026, SAP released security updates addressing critical vulnerabilities in its Commerce Cloud and other systems. Attackers can exploit these flaws, including CVE-2026-58231, to gain full control over instances without authentication. The vulnerabilities allow for malicious code injection and memory corruption, posing significant risks to SAP users. A total of 40 CVEs were addressed, with four classified as critical. Other affected components include the ABAP Platform and BusinessObjects Business Intelligence. SAP customers are advised to download the patches immediately to mitigate these risks. The vulnerabilities could lead to unauthorized access and system crashes, highlighting the urgency for organizations to act.

Key Points: • SAP released critical patches for 40 vulnerabilities on August 11, 2026. • CVE-2026-58231 allows unauthenticated attackers to execute malicious code. • Immediate patching is recommended to prevent unauthorized access and system crashes.

ThreatCluster AI How this analysis works

Timeline

2026-08-11
SAP releases security updates
SAP addresses 40 CVEs, including critical vulnerabilities allowing code injection and memory corruption.
Heise.De
2026-08-11
CVE-2026-58231 published
This critical vulnerability allows attackers to execute malicious code without authentication.
Heise.De
2026-08-11
CVE-2026-34265 published
Exploitation of this vulnerability can lead to system crashes in SAP NetWeaver and ABAP Platform.
Heise.De
2026-08-11
CVE-2026-44758 published
This vulnerability is part of the critical flaws affecting SAP's Manufacturing Integration and Intelligence.
Heise.De

Community

Browse all →