Cybersecurity & Protection

SAP Patch Day: Critical Flaw Makes Commerce Cloud Fully Compromisable

Aug 11, 2026 2 min read
All articles

On its latest patch day, SAP closed numerous security vulnerabilities in its business software. Particularly serious: a critical flaw lets attackers gain full control over Commerce Cloud instances. Matching security updates are available, and you should apply them promptly.

Critical vulnerabilities

In total, SAP lists 40 CVE numbers for closed vulnerabilities, four of which are rated critical. The most severe is a flaw in Commerce Cloud (CVE-2026-58231) with the maximum CVSS score of 10 out of 10. Attackers can target the platform without authentication and execute malicious code due to insufficient checks. That makes a complete compromise of affected instances possible.

The Manufacturing Integration and Intelligence component is also vulnerable through two code-execution flaws (CVE-2026-44772, CVE-2026-44758). Another vulnerability (CVE-2026-34265) in Application Server ABAP for SAP NetWeaver and ABAP Platform can lead to crashes if successfully exploited.

More updates and recommendation

Beyond that, SAP's developers fixed security issues in ABAP Platform, BusinessObjects Business Intelligence, and Social Intelligence, among others. In some of these, unauthorized access to sensitive data was possible, while in other cases malicious code could reach systems. SAP customers can find more information about the patched versions in the support portal. Given the maximum severity for Commerce Cloud, you shouldn't delay the update, especially since the flaw can be exploited without logging in.