Product1 distinct publisher3 min readUpdated
Five HotNews and nine High Priority notes land on Commerce Cloud, NetWeaver AS ABAP and MII, and two of the described fixes are not finished when the patch is applied.
The Product Desk · Product desk
Compiled by The Product DeskSomething wrong?How this is made
SAP published 33 new and updated security notes on its August 2026 Patch Day, five of them tagged HotNews and nine High Priority, according to analysis from Onapsis Research Labs [1]. That puts 14 of 33 notes, roughly 42 percent, in the top two severity bands [16], and the components named are ones with production dependencies rather than edge cases: Commerce Cloud, NetWeaver Application Server ABAP, and Manufacturing Integration and Intelligence [6][13][5].
The list also moved after release. Onapsis updated its write-up on 11 August 2026 at 12:55 CEST following SAP's publication of four additional notes [2], so a triage sheet assembled on patch-day morning was already incomplete by lunchtime.
Top of the stack is Note 3771065, scored CVSS 10.0, covering insufficient authorization checks and input validation in the SAP Commerce Cloud Data Hub Adapter; Onapsis says successful exploitation could allow arbitrary code execution and compromise of internal components [6]. The fix is not a single click: customers must move to the fixed Commerce Cloud release levels referenced in the note and then re-build and re-deploy [7]. Where that cannot happen this week, Onapsis points to an IP Filter Set in Commerce Cloud restricting access to the vulnerable endpoint as a temporary reduction in exposure, with further detail in SAP's FAQ for the note [8].
Two MII code injection notes follow, both patched with Onapsis Research Labs support [15]. Note 3765948, at CVSS 9.9, involves a servlet that can be made to fetch and process attacker-controlled content from an external source; a low-privileged attacker could run arbitrary commands on the host, with impact beyond the vulnerable component and, in Onapsis's description, total infrastructure compromise [9]. This one also has post-patch homework: administrators must maintain a new system property, Secure Transformer, listing the hosts allowed to serve XSL files [10]. Note 3758900, at CVSS 9.1, addresses server-side template injection and server-side request forgery in another MII servlet; the score is lower because higher privileges are required, and the patch removes the component outright [11]. In total, six MII vulnerabilities were fixed in collaboration with Onapsis, including two HotNews and three High Priority notes [5].
For basis teams, the note to argue about is 3714806, CVSS 9.8, a memory corruption defect in NetWeaver AS ABAP and ABAP Platform caused by logical errors in DIAG protocol parsing, reachable by an unauthenticated attacker and capable of disclosing system information or crashing the system [13]. Of the notes Onapsis details, it is the only one described as requiring no credentials at all [17], which is the argument for putting it ahead of items with higher scores on the change calendar.
Two more items to reconcile. Note 3747367, CVSS 9.9, was first issued on July's Patch Day and has been updated in its Validity and Solution sections [12], so anything filed as closed in July needs re-reading. And Note 3772411, CVSS 8.8, removes support for host expressions in the SQL Console of SAP ABAP Developer Tools, which had let a low-privileged attacker perform unauthorized database operations and read and modify sensitive data [14].
Watch three things. Whether SAP appends further notes to this cycle, as it did on 11 August [2]. Whether Commerce Cloud owners actually completed the re-build and re-deploy step rather than logging the note as applied [7]. And whether the Secure Transformer allowlist is populated after the MII patch, since the protection depends on it [10]. Onapsis's published detail begins with 3772411 among the High Priority notes and the text available to us stops mid-description [19]; the remaining eight need reading from SAP's own list.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Eleven of the twenty-nine new Security Notes were published in contribution with the Onapsis Research Labs.
Onapsis Research Labs supported SAP in patching fourteen vulnerabilities covered by eleven SAP Security Notes and one SAP Correction Note, including two tagged HotNews and three tagged High Priority.
Six vulnerabilities were fixed in SAP MII in collaboration with Onapsis Research Labs, including two HotNews and three High Priority Notes.
Onapsis Research Labs supported SAP in patching two of the three new HotNews Notes, both addressing critical code injection vulnerabilities in SAP Manufacturing Integration and Intelligence.
SAP published thirty-three new and updated SAP Security Notes on its August 2026 Patch Day, including five HotNews Notes and nine High Priority Notes.
Onapsis updated its article on August 11, 2026 at 12:55PM CEST following SAP's release of an additional four SAP Security Notes after the initial Patch Day release.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific and internally checkable, but single-source
Every substantive claim resolves to named SAP note numbers, CVSS scores, affected components and remediation steps, which is unusually verifiable detail, and the post timestamps its own revision after four late notes. Against that: there is exactly one publisher in the cluster, it is a party credited in eleven of the notes it reports, no SAP primary bulletin or CVE identifiers are supplied, the captured text is truncated before all nine High Priority Notes are described, and two ledger generalisations are contradicted by the post's own later paragraphs.
Patches published; customer uptake unobserved
Adoption evidence is entirely supply-side: notes shipped for a broad SAP product footprint, four more added after the initial release, six MII fixes delivered with Onapsis Research Labs, and two earlier notes re-released, which implies ongoing remediation churn on May and July items. Nothing in the supplied source measures how many customers have applied any note, completed the Commerce Cloud re-build/re-deploy, or configured the Secure Transformer allowlist, so the score reflects availability only and not observed deployment.
Mildly overstated by framing and derived counts
The underlying reporting is sober and score-anchored, so the gap is small. It is positive rather than zero because severity language such as 'total infrastructure compromise' describes worst-case CVSS scoring with no exploitation evidence supplied, because the five-HotNews headline blends new and updated notes while only three HotNews are new, and because two derived ledger claims overstate their precision — the 'only #3714806 is unauthenticated' reading and the 'two fixes need extra work' count are both undercut by the post's own #3773203 paragraph.
Vendor reporting on research it co-authored
The only publisher is Onapsis, a commercial SAP security vendor, and the post repeatedly foregrounds Onapsis Research Labs credit: eleven of twenty-nine new notes, fourteen vulnerabilities, two of three new HotNews. Monthly patch-day analysis of this kind is a demand-generation channel for SAP security tooling and services, and severity framing directly supports that. The disclosure is explicit rather than hidden, which limits the distortion, but no counterweight source exists in the cluster.
Moderate: precise details, no corroboration
Confidence is held down by single-publisher sourcing from an interested party, absent CVE mapping, truncated text that leaves the High Priority list incomplete, and two internally contradicted derived claims. It is not lower because patch-day facts of this type are routinely checkable against the cited note numbers, the post dates and discloses its own post-release update, and the core note-by-note descriptions are consistent within the source.
security
SAP's CVSS 10.0 Commerce Cloud bug needs a re-deploy, not just a patch window1 distinct publisher
build
A Commerce Cloud RCE chain reached a honeypot three days after the patch shipped1 distinct publisher
security
One packet reboots your Cisco VPN box, and Cisco will not say who is firing it1 distinct publisher
security
Cisco's control planes are the exposure: four criticals in Crosswork, four in Secure Workload1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 16, 2026