Skip to content

Product1 publisher3 min readPublished

Fourteen of SAP's 33 August notes are top-severity: build the named-system list this week

Five HotNews and nine High Priority notes land on Commerce Cloud, NetWeaver AS ABAP and MII, and two of the described fixes are not finished when the patch is applied.

The Product Desk · Product desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened

  • SAP published thirty-three new and updated SAP Security Notes on its August 2026 Patch Day, including five HotNews Notes and nine High Priority Notes.
  • Onapsis updated its article on August 11, 2026 at 12:55PM CEST following SAP's release of an additional four SAP Security Notes after the initial Patch Day release.
  • Eleven of the twenty-nine new Security Notes were published in contribution with the Onapsis Research Labs.
  • Onapsis Research Labs supported SAP in patching fourteen vulnerabilities covered by eleven SAP Security Notes and one SAP Correction Note, including two tagged HotNews and three tagged High Priority.
  • Six vulnerabilities were fixed in SAP MII in collaboration with Onapsis Research Labs, including two HotNews and three High Priority Notes.

Compiled by The Product DeskSomething wrong?How this is made

Why it matters

SAP published 33 new and updated security notes on its August 2026 Patch Day, five of them tagged HotNews and nine High Priority, according to analysis from Onapsis Research Labs [1]. That puts 14 of 33 notes, roughly 42 percent, in the top two severity bands [16], and the components named are ones with production dependencies rather than edge cases: Commerce Cloud, NetWeaver Application Server ABAP, and Manufacturing Integration and Intelligence [6][13][5].

The list also moved after release. Onapsis updated its write-up on 11 August 2026 at 12:55 CEST following SAP's publication of four additional notes [2], so a triage sheet assembled on patch-day morning was already incomplete by lunchtime.

Top of the stack is Note 3771065, scored CVSS 10.0, covering insufficient authorization checks and input validation in the SAP Commerce Cloud Data Hub Adapter; Onapsis says successful exploitation could allow arbitrary code execution and compromise of internal components [6]. The fix is not a single click: customers must move to the fixed Commerce Cloud release levels referenced in the note and then re-build and re-deploy [7]. Where that cannot happen this week, Onapsis points to an IP Filter Set in Commerce Cloud restricting access to the vulnerable endpoint as a temporary reduction in exposure, with further detail in SAP's FAQ for the note [8].

Two MII code injection notes follow, both patched with Onapsis Research Labs support [15]. Note 3765948, at CVSS 9.9, involves a servlet that can be made to fetch and process attacker-controlled content from an external source; a low-privileged attacker could run arbitrary commands on the host, with impact beyond the vulnerable component and, in Onapsis's description, total infrastructure compromise [9]. This one also has post-patch homework: administrators must maintain a new system property, Secure Transformer, listing the hosts allowed to serve XSL files [10]. Note 3758900, at CVSS 9.1, addresses server-side template injection and server-side request forgery in another MII servlet; the score is lower because higher privileges are required, and the patch removes the component outright [11]. In total, six MII vulnerabilities were fixed in collaboration with Onapsis, including two HotNews and three High Priority notes [5].

For basis teams, the note to argue about is 3714806, CVSS 9.8, a memory corruption defect in NetWeaver AS ABAP and ABAP Platform caused by logical errors in DIAG protocol parsing, reachable by an unauthenticated attacker and capable of disclosing system information or crashing the system [13]. Of the notes Onapsis details, it is the only one described as requiring no credentials at all [17], which is the argument for putting it ahead of items with higher scores on the change calendar.

Two more items to reconcile. Note 3747367, CVSS 9.9, was first issued on July's Patch Day and has been updated in its Validity and Solution sections [12], so anything filed as closed in July needs re-reading. And Note 3772411, CVSS 8.8, removes support for host expressions in the SQL Console of SAP ABAP Developer Tools, which had let a low-privileged attacker perform unauthorized database operations and read and modify sensitive data [14].

Watch three things. Whether SAP appends further notes to this cycle, as it did on 11 August [2]. Whether Commerce Cloud owners actually completed the re-build and re-deploy step rather than logging the note as applied [7]. And whether the Secure Transformer allowlist is populated after the MII patch, since the protection depends on it [10]. Onapsis's published detail begins with 3772411 among the High Priority notes and the text available to us stops mid-description [19]; the remaining eight need reading from SAP's own list.

Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories