SAP security advisory – August 2026 monthly rollup (AV26-798) – Update 1
Serial Number: AV26-798 Date: August 11, 2026 Updated: August 17, 2026 As of August 11, 2026, SAP is affected by vulnerabilities in the following products: SAP Commerce Cloud (Data Hub Adapter) Versions COM_CLOUD 2211 and 2211-JDK21 SAP Manufacturing Integration and Intelligence Versions XMII 15.4, 15.5, MII_ADMIN 15.4 and 15.5 SAP NetWeaver and ABAP Platform Versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18 and 9.19 SAP Manufacturing Integration and Intelligence Version MII 15.4, 15.5 SAP Change and Transport System Attach Tool (ctsattach) Version CTS_UPLOAD_CLT 1 SAP ABAP Developer Tools Versions AP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816 and SAP_BASIS 918, SAP_BASIS 920 SAP Commerce Cloud Versions OM_CLOUD 2211, 2211-JDK21 and DHUB_CLOUD 2211, 2211-JDK21 SAP BusinessObjects Business Intelligence Platform (Central Management Server) Versions AP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920, ENTERPRISE 430, 2025 and 2027 SAP Manufacturing Integration and Intelligence Versions MII 15.4 and 15.5 Update 1 Open-source reporting indicates that CVE-2026-58231 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SAP Security Patch Day - August 2026
CSIRTS triage
- What
- Multiple vulnerabilities affect multiple SAP products including Commerce Cloud, Manufacturing Integration and Intelligence, NetWeaver, ABAP Platform, Change and Transport System, and ABAP Developer Tools.
- Who is affected
- Organizations running affected versions of SAP Commerce Cloud, SAP XMII, SAP NetWeaver, SAP ABAP Platform, SAP CTS Attach Tool, and SAP ABAP Developer Tools.
- Urgency
- Moderate to high urgency pending severity classification; SAP monthly rollups typically address a range of functional and security issues.
- Action
- Review SAP security advisories and apply recommended patches for affected product versions.
AI-assisted analysis generated from the source advisory — verify against the original.
Details
Original advisory: https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-august-2026-monthly-rollup-av26-798
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-582310.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-58231 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapterncsc-nl
- criticalCVE-2026-58231: SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client…nvd
- unknownMultiple vulnerabilities in SAP products (August 11, 2026)cert-fr-avis
More from Canadian Centre for Cyber Security
- unknownWatchGuard security advisory (AV26-847)2026-08-25
- unknownOpenSSL security advisory (AV26-846)2026-08-25
- unknownGitea security advisory (AV26-845)2026-08-25
- unknownGoogle security advisory (AV26-844)2026-08-24
- criticalOracle security advisory – January 2026 quarterly rollup (AV26-042) – Update 22026-08-24