Ce mail provient de l'extérieur, restons vigilants

=====================================================================


                            CERT-Renater

                Note d'Information No. 2026/VULN837
_____________________________________________________________________

DATE                : 11/08/2026

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Systems running SAP products.
 
=====================================================================
https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html
_____________________________________________________________________


SAP Security Patch Day - August 2026

This post shares the information on security notes that remediate
vulnerabilities discovered in SAP products. SAP strongly recommends
that the customer visits the support portal and applies patches on
priority to protect their SAP landscape.

On 11th of August 2026, SAP security patch day saw the release of 28
new security notes and 1 Github security advisory. There are 2 updates
to previously released security notes.

Note#   Title   Priority    CVSS

3771065
[CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data
Hub Adapter)
Product - SAP Commerce Cloud (Data Hub Adapter)
Version(s) - COM_CLOUD 2211, 2211-JDK21
Critical             10.0

3765948
[CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing
Integration and Intelligence
Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5, MII_ADMIN 15.4, 15.5
Critical             9.9

3714806
[CVE-2026-34265] Memory Corruption vulnerability in Application Server
ABAP for SAP NetWeaver and ABAP Platform
Product - SAP NetWeaver and ABAP Platform
Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2,
7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19,
KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19
Critical             9.8

3758900
[CVE-2026-44758] Code Injection vulnerability in Manufacturing
Integration and Intelligence
Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5
Critical             9.1

3772411
[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP
Developer Tools
Product - SAP ABAP Developer Tools
Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752,
SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756,
SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918,
SAP_BASIS 920
High                  8.8

3773203
[CVE-2026-42945] Potential buffer overflow vulnerability affects
SAP Commerce Cloud in public‑cloud deployments with NGINX
Product - SAP Commerce Cloud
Version(s) - COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211,
2211-JDK21
High                   8.1

3727078
Update to Security Note released on July 2026 Patch Day:
[CVE-2026-58233] Remote Code Execution vulnerability in SAP
Change and Transport System Attach Tool (ctsattach)
Product - SAP Change and Transport System Attach Tool (ctsattach)
Version(s) - CTS_UPLOAD_CLT 1
High                   7.6

3756565
[CVE-2026-66763] Credentials disclosure in SAP BusinessObjects
Business Intelligence Platform (Central Management Server)
Product - SAP BusinessObjects Business Intelligence Platform
(Central Management Server)
Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752,
SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756,
SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918,
SAP_BASIS 920, ENTERPRISE 430, 2025, 2027
High                    7.9

3759854
[CVE-2026-44763] Directory Traversal vulnerability in SAP
Manufacturing Integration and Intelligence
Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5
High                    7.6

3758657
[CVE-2026-44765] Missing Authorization Check in SAP
Manufacturing Integration and Intelligence
Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5
High                    7.3

3758910
[CVE-2026-44764] Missing Authorization Check in SAP Manufacturing
Integration and Intelligence
Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5
High                     7.3

3786038
[CVE-2026-58230] Multiple vulnerabilities in SAP Business AI
Platform (Approuter)
Additional CVEs - CVE-2026-66775, CVE-2026-66778, CVE-2026-66760,
CVE-2026-66761, CVE-2026-66777, CVE-2026-66776, CVE-2026-66774,
CVE-2026-58237, CVE-2026-58238, CVE-2026-58239
Product - SAP Business AI Platform (Approuter)
Version(s) <23.0.0
High                      7.0

3753141
[CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects
Business Intelligence
Product - SAP BusinessObjects Business Intelligence
Version(s) - ENTERPRISE 430, 2025, 2027, ENTERPRISECLIENTTOOLS 430,
2025, 2027
Medium                     6.5

3770868
[CVE-2026-34480] Improper Output Encoding Vulnerability in SAP Commerce
Cloud and SAP Data Hub (Apache Log4j Core)
Product - SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core)
Version(s) - COM_CLOUD 2211, 2211-JDK21, DHUB_CLOUD 2211
Medium                     6.5

3757815
[CVE-2026-5598] Potential Information Disclosure vulnerability in SAP
Commerce Cloud (Bouncy Castle Java library)
Product - SAP Commerce Cloud (Bouncy Castle Java library)
Version(s) - COM_CLOUD 2211, 2211-JDK21
Medium                     6.5

3721424
[CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver
Application Server ABAP
Product - SAP NetWeaver Application Server ABAP
Version(s) - SAP_UI 754, 755, 756, 757, 758, 816, EP-FLP 7.50, SAP_BASIS
731, AJAX-RUNTIME 7.50
Medium                     6.3

3766473
[CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence
Product - SAP Social Intelligence
Version(s) - S4FND 102, 103, 104, 105, 106, 107, 108, 109
Medium                     6.3

3758318
[CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver
AS Java (Adobe Document Services)
Product - SAP NetWeaver AS Java (Adobe Document Services)
Version(s) - ADSSAP 7.50
Medium                     6.3

3772071
[CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5
Product - SAPUI5
Version(s) - SAP_UI 750, 754, 755, 756, 757, 758, 816, UI_700 200
Medium                    6.1

GHSA-hc5j-q32w-c25v
[CVE-2026-66773] Server-controlled `__next` URL is not checking
cross-origin
Library – pyodata (pip)
Version(s) < 1.11.2
Medium                    5.9

3745182
[CVE-2026-58236] OS Command Injection vulnerability in Application Server
ABAP of SAP NetWeaver and ABAP Platform
Product - SAP NetWeaver Application Server ABAP and ABAP Platform
Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, KERNEL
7.22, 7.53, 7.54, 7.77, 7.93, 9.16
Medium                    5.5

3540688
Update to Security Note released on July 2025 Patch Day:
[CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework
Product – SAP FICA ODN framework
Versions – SAPSCORE 132, S4CORE 102, 103, 104, 105, 106, 107, 108, FI-CA 606,
616, 617, 618
Medium                    5.5

3725940
[CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service
Product - SAPSPrint Service
Version(s) – SAPSPRINT 8.00, 8.10
Medium                    5.3

3756674
[CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform
Product - SAP ABAP Platform
Version(s) - KRNL64UC 7.53, KERNEL 7.53, 7.54, 7.77
Medium                    5.3

3778462
[Multiple CVEs] Security Vulnerabilities in SAP Commerce Cloud (Search
and Navigation)
Related CVEs - CVE-2026-33871, CVE-2025-58057
Product - SAP Commerce Cloud (Search and Navigation)
Version(s) - COM_CLOUD 2211, 2211-JDK21
Medium                    4.8

3669608
[CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess
Bank Statement Items)
Product - SAP S/4 HANA (Reprocess Bank Statement Items)
Version(s) - S4CORE 104, 105, 106, 107, 108, 109
Medium                    4.3

3770649
[CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects
Business Intelligence Platform (Admin Tools)
Product - SAP S/4 HANA (Reprocess Bank Statement Items), SAP BusinessObjects
Business Intelligence Platform (Admin Tools)
Version(s) - S4CORE 104, 105, 106, 107, 108, 109, ENTERPRISE 430, 2025
Medium                    4.3

3781137
[CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration
and Intelligence (MII)
Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5
Medium                     4.3

3752864
[CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform
(Change and Transport System - Customer Transport Integration Wizard)
Product - SAP NetWeaver and ABAP Platform (Change and Transport System -
Customer Transport Integration Wizard
Version(s) - SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752,
SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757,
SAP_BASIS 758, SAP_BASIS 816
Medium                      4.2

3763028
[CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and
Optimization (Model Mix Planning)
Product - SAP Advanced Planning and Optimization (Model Mix Planning)
Version(s) - SCMAPO 713, 714, S4CORE 102, 103, 104, S4COREOP 104, 105,
106, 107, 108, 109, SCM 700, 701, 702, 712
Low                         3.8

3739913
[CVE-2026-44762] Security Misconfiguration in SAP Data Services Management
Console
Product - SAP Data Services Management Console
Version(s) - SBOP_DS_MANAGEMENT_CONSOLE 4.3, 2025
Low                          3.7


To know more about the security researchers and research companies
who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud
services. Secure configuration is essential to ensuring secure
operation and data integrity. We have therefore documented
security recommendations that are consolidated in this document
to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can
write to secure@sap.com.



=========================================================

+ CERT-RENATER        |    tel : 01-53-94-20-44         +
+ 23/25 Rue Daviel    |    fax : 01-53-94-20-41         +
+ 75013 Paris         |   email:cert@support.renater.fr +
=========================================================




