CVE-2026-58248
An attacker can exploit multiple vulnerabilities in SAP Software to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information or credentials, manipulate data, perform SQL injection or Cross-Site Scripting attacks, or cause a Denial of Service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in SAP software enable arbitrary code execution, privilege escalation, authentication bypass, information disclosure, SQL injection, cross-site scripting, and denial of service.
- Who is affected
- Deployments of SAP software affected by the August 2026 patch day advisories.
- Urgency
- High urgency; vulnerabilities span critical impact areas including code execution and credential disclosure.
- Action
- Apply SAP security patches from the August 2026 Patch Day addressing CVE-2026-34265, CVE-2026-40130, CVE-2026-44758, CVE-2026-44762, CVE-2026-44763, CVE-2026-44764, CVE-2026-44765, and CVE-2026-58230.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-58248
Get an email if CVE-2026-58248 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
Advisory coverage (3)
- critical[NEW] [high] SAP Patch Day August 2026: Multiple vulnerabilitiescert-bund · 2026-08-17
- mediumCVE-2026-58248: SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged …nvd · 2026-08-11
- unknownMultiple vulnerabilities in SAP products (August 11, 2026)cert-fr-avis · 2026-08-11
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-58248)