[NEW] [high] SAP Patch Day August 2026: Multiple vulnerabilities
An attacker can exploit multiple vulnerabilities in SAP Software to execute arbitrary code, escalate privileges, bypass security measures, disclose confidential information or credentials, manipulate data, perform SQL injection or Cross-Site Scripting attacks, or cause a Denial of Service condition.
CSIRTS triage
- What
- Multiple vulnerabilities in SAP software enable arbitrary code execution, privilege escalation, authentication bypass, information disclosure, SQL injection, cross-site scripting, and denial of service.
- Who is affected
- Deployments of SAP software affected by the August 2026 patch day advisories.
- Urgency
- High urgency; vulnerabilities span critical impact areas including code execution and credential disclosure.
- Action
- Apply SAP security patches from the August 2026 Patch Day addressing CVE-2026-34265, CVE-2026-40130, CVE-2026-44758, CVE-2026-44762, CVE-2026-44763, CVE-2026-44764, CVE-2026-44765, and CVE-2026-58230.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2746
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-342650.44% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 37% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-401300.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-447580.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-447620.14% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 4% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-447630.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 21% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-447640.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-447650.28% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 20% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-582300.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 16% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-582350.17% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 7% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-582360.38% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 31% of all EPSS-scored CVEs.
Referenced CVEs
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- mediumCVE-2026-66779: Due to a Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP, an…nvd
- mediumCVE-2026-66778: SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic…nvd
- mediumCVE-2026-66777: SAP Approuter does not sufficiently validate certain incoming requests before forwarding them …nvd
- mediumCVE-2026-66776: SAP Approuter does not consistently enforce integrity verification on certain session-related …nvd
- mediumCVE-2026-66775: SAP Approuter does not enforce cross-site request forgery protection on the authentication flo…nvd
- lowCVE-2026-66774: SAP Approuter does not consistently handle certain error conditions. An attacker with low priv…nvd
- mediumCVE-2026-66773: A malicious or compromised OData service could disclose sensitive authentication information a…nvd
- mediumCVE-2026-66772: SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient a…nvd
- mediumCVE-2026-66771: SAPUI5 allows a key user with content adaptation privileges to inject malicious script content…nvd
- mediumCVE-2026-66770: Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker co…nvd
- mediumCVE-2026-66764: Reprocess Bank Statement Items in SAP S/4HANA does not perform the necessary authorization che…nvd
- highCVE-2026-66763: SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associ…nvd
Recent advisories for SAP Patch Day
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- high[NEW] [high] SAP Patch Day July 2026cert-bund · 2026-07-29
More from CERT-Bund (BSI) Security Advisories
- high[NEW] [high] GStreamer: Multiple Vulnerabilities2026-08-17
- high[NEW] [high] Golang Go: Multiple vulnerabilities2026-08-17
- medium[NEW] [medium] Apache Struts: Multiple vulnerabilities2026-08-17
- high[NEW] [high] PostgreSQL: Multiple vulnerabilities2026-08-17
- high[UPDATE] [high] Oracle PeopleSoft: Multiple Vulnerabilities2026-08-17