SAP Releases August 2026 Security Patch Day Advisories Including Four Critical Vulnerabilities
SAP has released its monthly security update on August 11, 2026, publishing a total of 28 new security advisories. Four of these advisories were rated Critical, the highest severity level in SAP's four-tier scale.
The update coincides with the traditional Patch Tuesday cycle observed by many vendors on the second Tuesday of each month. Among the 28 advisories are one new entry originally published on GitHub and two updates to previously released advisories.
Critical Vulnerabilities Detailed
The highest-rated issue, CVE-2026-58231, was found in SAP Commerce Cloud (Data Hub Adapter). It involves an authorization bypass that received the maximum CVSS v3.0 base score of 10.0.
Two code injection vulnerabilities were disclosed in SAP Manufacturing Integration and Intelligence:
- CVE-2026-44772 with a CVSS score of 9.9
- CVE-2026-44758 with a CVSS score of 9.1
Additionally, a memory corruption vulnerability tracked as CVE-2026-34265 affects SAP NetWeaver and the ABAP Platform, rated at CVSS 9.8.
Organizations running affected SAP products are strongly encouraged to apply the patches as soon as possible to mitigate these high-impact issues.
Related articles
WordPress 7.0.4 Released to Patch High-Severity RCE Vulnerability CVE-2026-65640
The WordPress development team has issued version 7.0.4 to address a remote code execution vulnerability tracked as CVE-2026-65640. The flaw affects installations that use the Imagick and Ghostscript image-processing components and grants code execution to users with Author privileges or higher. An attacker can upload a specially crafted PostScript file to trigger arbitrary code execution on the server. The vulnerability received a CVSS v3.0 base score of 8.8 and is rated High severity. Administrators are urged to update immediately, either manually through the dashboard or via automatic background updates. Backported fixes for the 4.7 branch are also in preparation and will be released soon.
AI Uncovers Zoom Vulnerabilities Allowing Silent Device Takeover via Screen Sharing Annotations
Researchers at A Security identified multiple vulnerabilities in Zoom that enabled attackers to compromise participant devices during video calls without any user interaction. The flaws resided in the shared annotations protocol used for drawing and marking on shared screens. Victims only needed to join a meeting where screen sharing was active, affecting both regular participants and meeting organizers. The discovery was notable because it relied on publicly available AI models, requiring fewer than 20 prompts to locate the issues and build a working exploit prototype. The vulnerabilities impacted Zoom clients across Windows, macOS, Linux, iOS, and Android. Zoom addressed the problems through security bulletin ZSB-26015 with server-side and client patches. The research highlights how AI can dramatically accelerate vulnerability discovery compared to traditional manual analysis.
Attackers Exploit Critical CVE-2026-59310 in VMware vCenter for Persistent Remote Access
A critical vulnerability identified as CVE-2026-59310 in Broadcom VMware vCenter Server is being actively exploited in the wild against internet-exposed instances. The flaw resides in the Syslog server component and enables remote code execution through a path traversal weakness, carrying a CVSS score of 9.8. Attackers have been observed deploying malicious cron jobs and the reverse_ssh tool to establish persistent outbound command-and-control channels since early August 2026. The campaign has impacted 361 unique IP addresses across 47 countries, with notable concentrations in Germany, the United States, Turkey, Iran, and France. Broadcom has released patches under advisory VMSA-2026-0006.1, which also addresses the related CVE-2026-59309, and strongly recommends immediate updates along with network segmentation and log reviews. No workarounds exist, making prompt patching the only effective mitigation.
SAP Releases August Security Update Patching 28 Vulnerabilities Including Critical CVSS 10 Flaw
SAP has issued a broad security update to address multiple critical vulnerabilities that could enable code injection, memory corruption, and privilege escalation across enterprise systems. The August package includes 28 new security notes along with a GitHub advisory and two prior fix updates. The highest-severity issue, CVE-2026-58231, carries a maximum CVSS score of 10 and affects the Data Hub Adapter in SAP Commerce Cloud versions 2211 and 2211-JDK21, allowing remote exploitation without user interaction due to improper authorization. Another critical flaw, CVE-2026-44772 rated 9.9, impacts SAP Manufacturing Integration and Intelligence 15.4 and 15.5, permitting malicious code injection into industrial process monitoring systems. Additional vulnerabilities rated 9.1 and lower cover directory traversal, SQL injection, XSS, XXE, hardcoded credentials, and OS command injection across various corporate components. Administrators are advised to identify affected systems and prioritize installation of the critical patches first.