
SAP released its August 2026 Patch Day on 11 August, issuing 28 security notes that address multiple flaws across its product suite. The most severe flaw is CVE-2026-58231, rated CVSS 10.0, which affects SAP Commerce Cloud.
CVE-2026-58231 results from an missing authorisation check in the Web Dynpro layer that lets an unauthenticated user bypass the login screen and obtain administrative privileges. Attackers can manipulate session tokens to pose as legitimate administrators and then view order histories, alter pricing rules or create fictitious accounts. The vulnerability does not require any valid credentials and can be triggered over HTTP or HTTPS.
The same Patch Day also resolves two code injection bugs in the Application Server ABAP stack, each scored CVSS 9.1, where malicious RFC calls can lead to arbitrary code execution on the underlying host. A separate memory corruption defect in the ABAP kernel, rated CVSS 9.0, could allow an attacker to inject and run shellcode after sending a specially crafted SOAP request. Together these flaws impact core ERP modules such as finance, procurement and supply chain management.
SAP has not detected any active exploitation of these vulnerabilities in the wild and no threat actor groups have been publicly linked to them. However, proof‑of‑concept snippets for comparable ABAP issues are present in public repositories, which increases the likelihood that automated scanners will attempt to weaponise the details once they become widely known. This release represents SAP’s largest monthly update this year, part of a broader effort to strengthen cloud security after several high‑profile incidents in 2025.
Security teams should prioritize the Commerce Cloud patch and apply it to all internet‑facing storefronts as soon as possible, ideally within the next seven days. Administrators of ABAP‑based systems must upgrade the kernel to the latest support package level, restart the affected services and verify that any custom code remains functional. Limiting RFC and SOAP ports to trusted networks and enabling strict ingress filtering can reduce exposure while the patches are rolled out. Monitoring for failed login attempts and unusual token usage in Commerce Cloud can