We've created the first of its kind, SecurityBridge Cloud Platform, designed to prioritize SAP patches, updates, and remediation strategies that help prevent disruptions to critical business systems. Our security advisories provide SAP users with valuable insights into the security and business implications of operating SAP.

The user interface is designed to be as intuitive as possible, but we’d love to hear your feedback and suggestions.

×

Yikes, there is work to do!
This time we found critical correction advisiories. We count 34 and the highest CVSS score is 10.0.

 

Severity
SAP© Security advisories 34
 System Types
Affected SAP© system types

 

3771065
CVSS
10.0

Affected system type SAP Commerce
Patchday 2026-08
Released on 2026/08/11
Description 3771065 - [CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
3747367
CVSS
9.9

Affected system type Kernel
Patchday 2026-08
Released on 2026/07/14
Description 3747367 - [CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
3765948
CVSS
9.9

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3765948 - [CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence
3714806
CVSS
9.8

Affected system type Kernel / ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3714806 - [CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
3758900
CVSS
9.1

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758900 - [CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence
3772411
CVSS
8.8

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3772411 - [CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools
3732471
CVSS
8.2

Affected system type ABAP
Patchday 2026-08
Released on 2026/05/12
Description 3732471 - [CVE-2026-34259] OS Command Injection Vulnerability in SAP Forecasting & Replenishment
3773203
CVSS
8.1

Affected system type SAP Commerce
Patchday 2026-08
Released on 2026/08/11
Description 3773203 - [CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‚Äëcloud deployments with NGINX
3756565
CVSS
7.9

Affected system type BI/BO platform
Patchday 2026-08
Released on 2026/08/11
Description 3756565 - [CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
3773304
CVSS
7.6

Affected system type SAP Change and...
Patchday 2026-08
Released on 2026/07/14
Description 3773304 - [CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)
3759854
CVSS
7.6

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3759854 - [CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence
3485073
CVSS
7.5

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/25
Description [CVE-2026-66766] Denial of Service (DoS) due to use of third-party component in SAP S/4HANA (Manage Supply Protection)
3758910
CVSS
7.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758910 - [CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
3758657
CVSS
7.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758657 - [CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
3786038
CVSS
7.0

Affected system type SAP Approuter
Patchday 2026-08
Released on 2026/08/11
Description 3786038 - [CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)
3753141
CVSS
6.5

Affected system type BI/BO platform
Patchday 2026-08
Released on 2026/08/11
Description 3753141 - [CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence
3758318
CVSS
6.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3758318 - [CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
3721424
CVSS
6.3

Affected system type SAP NetWeaver
Patchday 2026-08
Released on 2026/08/11
Description 3721424 - [CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
3766473
CVSS
6.3

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3766473 - [CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence
3772071
CVSS
6.1

Affected system type SAP UI5
Patchday 2026-08
Released on 2026/08/11
Description 3772071 - [CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5
3745182
CVSS
5.5

Affected system type Kernel / ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3745182 - [CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
3540688
CVSS
5.5

Affected system type ABAP
Patchday 2026-08
Released on 2025/07/22
Description 3540688 - [CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework
3725940
CVSS
5.3

Affected system type SAPSprint
Patchday 2026-08
Released on 2026/08/11
Description 3725940 - [CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service
3756674
CVSS
5.3

Affected system type Kernel / ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3756674 - [CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform
3781137
CVSS
4.3

Affected system type Java
Patchday 2026-08
Released on 2026/08/11
Description 3781137 - [CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)
3770649
CVSS
4.3

Affected system type BI/BO platform
Patchday 2026-08
Released on 2026/08/11
Description 3770649 - [CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)
3669608
CVSS
4.3

Affected system type ABAP
Patchday 2026-08
Released on 2025/11/19
Description 3669608 - [CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
3413033
CVSS
4.3

Affected system type ABAP
Patchday 2026-08
Released on 2026/07/28
Description 3413033 - [CVE-2026-58246 ] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
3752864
CVSS
4.2

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3752864 - [CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)
3763028
CVSS
3.8

Affected system type ABAP
Patchday 2026-08
Released on 2026/08/11
Description 3763028 - [CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
3739913
CVSS
3.7

Affected system type SAP Data Services
Patchday 2026-08
Released on 2026/08/11
Description 3739913 - [CVE-2026-44762 ] Security Misconfiguration in SAP Data Services Management Console
3770868
CVSS
0.0

Affected system type SAP Commerce Cloud
Patchday 2026-08
Released on 2026/08/11
Description 3770868 - [CVE-2026-34480] Improper Output Encoding Vulnerability in SAP Commerce Cloud and SAP Data Hub (Apache Log4j Core)
3778462
CVSS
0.0

Affected system type SAP Commerce Cloud
Patchday 2026-08
Released on 2026/08/11
Description 3778462 - [Multiple CVEs] Security Vulnerabilities in SAP Commerce Cloud (Search and Navigation)
3757815
CVSS
0.0

Affected system type SAP Commerce Cloud
Patchday 2026-08
Released on 2026/08/11
Description 3757815 - [CVE-2026-5598] Potential Information Disclosure vulnerability in SAP Commerce Cloud (Bouncy Castle Java library)