CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

SAP security advisory – August 2026 monthly rollup (AV26-798) – Update 1

unknownpublic exploitCVE-2026-58231
Serial Number: AV26-798 Date: August 11, 2026 Updated: August 17, 2026 As of August 11, 2026, SAP is affected by vulnerabilities in the following products: SAP Commerce Cloud (Data Hub Adapter) Versions COM_CLOUD 2211 and 2211-JDK21 SAP Manufacturing Integration and Intelligence Versions XMII 15.4, 15.5, MII_ADMIN 15.4 and 15.5 SAP NetWeaver and ABAP Platform Versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18 and 9.19 SAP Manufacturing Integration and Intelligence Version MII 15.4, 15.5 SAP Change and Transport System Attach Tool (ctsattach) Version CTS_UPLOAD_CLT 1 SAP ABAP Developer Tools Versions AP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816 and SAP_BASIS 918, SAP_BASIS 920 SAP Commerce Cloud Versions OM_CLOUD 2211, 2211-JDK21 and DHUB_CLOUD 2211, 2211-JDK21 SAP BusinessObjects Business Intelligence Platform (Central Management Server) Versions AP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920, ENTERPRISE 430, 2025 and 2027 SAP Manufacturing Integration and Intelligence Versions MII 15.4 and 15.5 Update 1 Open-source reporting indicates that CVE-2026-58231 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SAP Security Patch Day - August 2026

CSIRTS triage

What
Multiple vulnerabilities affect multiple SAP products including Commerce Cloud, Manufacturing Integration and Intelligence, NetWeaver, ABAP Platform, Change and Transport System, and ABAP Developer Tools.
Who is affected
Organizations running affected versions of SAP Commerce Cloud, SAP XMII, SAP NetWeaver, SAP ABAP Platform, SAP CTS Attach Tool, and SAP ABAP Developer Tools.
Urgency
Moderate to high urgency pending severity classification; SAP monthly rollups typically address a range of functional and security issues.
Action
Review SAP security advisories and apply recommended patches for affected product versions.

AI-assisted analysis generated from the source advisory — verify against the original.

Details

Source
Canadian Centre for Cyber Security (CA · national-cert · site)
Severity
unknown
Published
2026-08-17
Exploitation
Not in CISA KEV at last sync

Original advisory: https://cyber.gc.ca/en/alerts-advisories/sap-security-advisory-august-2026-monthly-rollup-av26-798

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-58231coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

More from Canadian Centre for Cyber Security