Critical SAP flaw lets anyone take over Commerce Cloud

SAP has shipped its August 2026 Security Patch Day, and the top item is as bad as the scoring system allows. CVE-2026-58231 is an improper authorization flaw in the Data Hub Adapter of SAP Commerce Cloud, rated CVSS 10.0, which a remote attacker holding no prior privileges could use to fully compromise the confidentiality, integrity and availability of the system. The affected builds are COM_CLOUD 2211 and 2211-JDK21.

The release, published on 11 August 2026, carries 28 new security notes, a GitHub security advisory and two updates to previously disclosed issues. It covers software that sits at the centre of large enterprises: SAP Commerce Cloud, NetWeaver, the ABAP Platform, Manufacturing Integration and Intelligence (MII), BusinessObjects and the Business AI Platform. Peru's national digital security centre, the CNSD, relayed the release to national operators in integrated alert 145-2026, which is the source for the severity figures below. SAP's own security notes carry the per fix detail and the patch levels to apply.

What's affected

The high severity band adds CVE-2026-58243 (CVSS 8.8), privilege escalation in SAP ABAP Developer Tools; CVE-2026-42945 (CVSS 8.1), a possible buffer overflow in public cloud Commerce Cloud deployments that use NGINX; CVE-2026-66763 (CVSS 7.9), credential exposure in BusinessObjects BI Platform; CVE-2026-58233 (CVSS 7.6), remote code execution in the Change and Transport System attach tool; CVE-2026-44763 (CVSS 7.6), directory traversal in MII; and CVE-2026-44764 with CVE-2026-44765 (both CVSS 7.3), insufficient authorization controls in MII. Medium and low severity notes cover SQL injection in SAP Social Intelligence, cross site scripting in SAPUI5, an XML external entity issue in BusinessObjects and operating system command injection in NetWeaver AS ABAP and the ABAP Platform.

Why it matters

Two of the four critical flaws are in MII, the layer that connects SAP business systems to plant floor equipment, which puts code execution uncomfortably close to manufacturing operations. The NetWeaver and ABAP Platform memory corruption issue is the broadest by version range, and CNSD notes that a flaw of that kind in a central application server can be used to run malicious code and then move laterally deeper into the estate. Commerce Cloud, meanwhile, is customer facing by design, so the CVSS 10.0 flaw sits on the part of an SAP landscape most likely to be reachable from the internet.

What you should do

CNSD's advice is to prioritize the four critical notes first, CVE-2026-58231, CVE-2026-44772, CVE-2026-34265 and CVE-2026-44758, then audit for SAP systems exposed directly to the internet, giving precedence to Commerce Cloud, NetWeaver and MII instances. Apply the fixes through the official SAP security notes for each affected component. No exploitation of any of these issues has been reported, and neither SAP nor CNSD has published exploitation detail, so patch planning rather than incident response is the right posture today.

It lands the same week Microsoft cleared 421 flaws in its own August release, making this a heavy patch cycle for enterprise IT teams. Regional context for the alerting authority sits on our Peru country profile.

This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.

Read the full analysis on IntelFusions