SAP recently announced the release of 28 new security notes addressing critical vulnerabilities in its software, including four critical issues with CVSS scores ranging from 9.1 to 10.0. The most severe vulnerability, CVE-2026-58231, allows remote attackers to bypass authentication in SAP Commerce Cloud. Other critical flaws include two code injection vulnerabilities and a memory corruption issue in Application Server ABAP.
The company also updated previous security notes and released notes on high-severity flaws in various platforms. No current exploits of these vulnerabilities have been reported.