Heise.De
Critical SAP Vulnerabilities Expose Commerce Cloud to Malicious Code Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On August 11, 2026, SAP released security updates addressing critical vulnerabilities in its Commerce Cloud and other systems. Attackers can exploit these flaws, including CVE-2026-58231, to gain full control over instances without authentication. The vulnerabilities allow for malicious code injection and memory corruption, posing significant risks to SAP users. A total of 40 CVEs were addressed, with four classified as critical. Other affected components include the ABAP Platform and BusinessObjects Business Intelligence. SAP customers are advised to download the patches immediately to mitigate these risks. The vulnerabilities could lead to unauthorized access and system crashes, highlighting the urgency for organizations to act.
Key Points: • SAP released critical patches for 40 vulnerabilities on August 11, 2026. • CVE-2026-58231 allows unauthenticated attackers to execute malicious code. • Immediate patching is recommended to prevent unauthorized access and system crashes.