Summary
- CVE-2026-58231 in the SAP Commerce Cloud Data Hub Adapter carries a CVSS score of 10.0.
- SAP’s August Patch Day includes 28 new security notes, a GitHub advisory, and two updates to earlier notes.
- The release also contains critical issues in Manufacturing Integration and Intelligence and NetWeaver/ABAP infrastructure, broadening the patching requirement beyond Commerce Cloud.
SAP has fixed a maximum-severity authorisation vulnerability in Commerce Cloud as part of an August security release containing several critical issues across software used in commerce, manufacturing, and core enterprise environments.
SAP published 28 new security notes and one GitHub security advisory on 11 August, alongside two updates to previously issued notes. The highest-rated new issue is CVE-2026-58231, an improper-authorisation vulnerability in the SAP Commerce Cloud Data Hub Adapter with a CVSS score of 10.0.
The affected Commerce Cloud versions listed by SAP are COM_CLOUD 2211 and 2211-JDK21. SAP classifies the issue as critical and directs customers to its support portal for the relevant security note and remediation. There is no evidence in the vendor’s public Patch Day material that CVE-2026-58231 is being exploited in the wild, so the severity rating should not be conflated with confirmed attacker activity.
The release is broader than a single commerce vulnerability. SAP also rates CVE-2026-44772, a code-injection flaw in Manufacturing Integration and Intelligence, at 9.9. A memory-corruption vulnerability affecting Application Server ABAP for SAP NetWeaver and ABAP Platform, CVE-2026-34265, carries a 9.8 score, while another Manufacturing Integration and Intelligence code-injection issue is rated 9.1.
Other high-severity fixes affect ABAP Developer Tools, Commerce Cloud deployments using NGINX, the Change and Transport System Attach Tool, BusinessObjects, and additional Manufacturing Integration and Intelligence functions. SAP’s security release consequently spans systems that can sit in very different parts of an organisation, from customer-facing commerce platforms to manufacturing integration and internal enterprise administration.
That range makes SAP patching less straightforward than a conventional endpoint update. Enterprise SAP landscapes often contain multiple products, customised applications, integrations, and business processes with strict availability requirements. A critical security note can therefore create a change-management problem in which organisations must establish exposure, test remediation, plan downtime where required, and account for dependencies before deploying fixes.
Commerce Cloud’s position is particularly relevant because authorisation failures can affect the boundary between what an authenticated or interacting user is permitted to do and what the platform actually allows. A CVSS score of 10 indicates the potential technical consequence under the scoring model, but the operational risk for an individual organisation still depends on whether the affected Data Hub Adapter is deployed, how it is configured, and what systems or data sit behind it.
The manufacturing vulnerabilities have a different consequence profile. SAP Manufacturing Integration and Intelligence is designed to connect manufacturing information with enterprise processes, giving vulnerabilities in that layer potential relevance to production environments and operational workflows. That does not mean a software flaw automatically creates a direct industrial-control-system compromise, but it increases the importance of understanding where the affected application sits between plant information and business systems.
SAP has repeatedly advised customers to prioritise security notes according to the affected landscape rather than treating Patch Day as a uniform monthly update. The August release reinforces that approach: several critical issues appear across distinct products, and a business may be exposed to none, one, or several depending on its architecture.
For European enterprises, the practical task is inventory rather than headline severity alone. SAP remains deeply embedded across manufacturing, retail, logistics, finance, and other sectors, while complex implementations can persist for years. The August fixes need to be mapped against the systems actually in service so that a maximum-severity Commerce Cloud flaw and critical manufacturing or NetWeaver issues do not disappear into a generic monthly patch queue.



