Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Once a $2.3 Billion Network, Ethereum Layer-2 Blast Is Shutting Down

    October 2, 2026

    Young Yosemite toads survive winter, then emerge with a deadly fungus

    October 2, 2026

    Vietnam’s fishers face rising costs, declining catches and a contested sea

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Once a $2.3 Billion Network, Ethereum Layer-2 Blast Is Shutting Down
    • Young Yosemite toads survive winter, then emerge with a deadly fungus
    • Vietnam’s fishers face rising costs, declining catches and a contested sea
    • The Guardian view on the Conservative conference: a party still searching for a purpose | Editorial
    • Video supposedly showing BBC News linking Indian passenger to Flydubai attack is a deepfake – Full Fact
    • Top Democrats slam ‘Trump’s failing economic agenda’ after weaker-than-expected jobs growth – US politics live | Trump administration
    • ‘Maxi merde’: French presidential campaign rattled by a week of chaos – POLITICO
    • Unusual Issues at War Court Stand Out as a Case Finally Heads to Trial
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory.

    Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most severe of which is CVE-2026-58231 (CVSS score of 10/10), an improper authorization issue in SAP Commerce Cloud (Data Hub Adapter).

    The bug could allow remote attackers to bypass authentication, likely leading to code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the application.

    SAP also addressed two critical code injection flaws in Manufacturing Integration and Intelligence, tracked as CVE-2026-44772 (CVSS score of 9.9/10) and CVE-2026-44758 (CVSS score of 9.1/10).

    Vulnerable servlets allow attackers to submit specially crafted input, leading to the execution of arbitrary commands on the underlying host and total infrastructure compromise. While the bugs are similar, one requires higher privileges to be exploited, application security firm Onapsis explains.

    The fourth critical defect is CVE-2026-34265 (CVSS score of 9.8/10), which is described as a memory corruption issue in Application Server ABAP for NetWeaver and ABAP Platform.

    Advertisement. Scroll to continue reading.

    Rooted in logical errors in DIAG protocol parsing, the vulnerability can be exploited without authentication to disclose sensitive information or crash the system, impacting application confidentiality, integrity, and availability.

    Before this month’s patches, SAP updated a critical security note released on the July 2026 Patch Day to resolve a critical memory corruption bug in NetWeaver Application Server ABAP. The update contains additional information.

    On Tuesday, SAP also released eight notes dealing with high-severity flaws in ABAP Developer Tools, Commerce Cloud, Change and Transport System Attach Tool, BusinessObjects, Manufacturing Integration and Intelligence, and Business AI Platform (Approuter).

    The first seven notes deal with privilege escalation, buffer overflow, remote code execution (RCE), credentials disclosure, directory traversal, and missing authorization check issues, while the seventh resolves 11 security defects in Approuter.

    The remaining notes released on SAP’s August 2026 Patch Day resolve medium- and low-severity vulnerabilities. SAP makes no mention of any of these flaws being exploited in the wild.

    Related: Cisco Warns of High-Severity ClamAV Vulnerabilities With Public PoC

    Related: Metabase Patches Vulnerability Exploited as Zero-Day

    Related: CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability

    Related: Critical One-Click Vulnerability in Atlassian’s Rovo AI Exposed Enterprise Data

    Code Corruption critical Injection memory Patches SAP Vulnerabilities
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    SWIFT Banking & Government Middleware Enables RCE

    In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

    US sanctions Tren de Aragua gang members in ATM hacks crackdown

    Vulnerability Backlogs Are an Ownership Problem

    macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

    OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Once a $2.3 Billion Network, Ethereum Layer-2 Blast Is Shutting Down

    October 2, 2026

    Young Yosemite toads survive winter, then emerge with a deadly fungus

    October 2, 2026

    Vietnam’s fishers face rising costs, declining catches and a contested sea

    October 2, 2026

    The Guardian view on the Conservative conference: a party still searching for a purpose | Editorial

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Once a $2.3 Billion Network, Ethereum Layer-2 Blast Is Shutting Down

    October 2, 2026

    Young Yosemite toads survive winter, then emerge with a deadly fungus

    October 2, 2026

    Vietnam’s fishers face rising costs, declining catches and a contested sea

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.