Recommendation for SAP Product Security Updates
Overview
SAP has released security updates to address vulnerabilities found in several of its products. Environments using these products should be updated to the latest version.
Affected Products and Vulnerabilities
- SAP NetWeaver and ABAP Platform: KRNL64NUC 7.22, 7.22EXT. KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19. KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, CVE-2026-34265 in version 9.19 Is a memory corruption vulnerability.
- SAP Manufacturing Integration and Intelligence: CVE-2026-44758 in XMII 15.4 And 15.5 Is a code injection vulnerability. CVE-2026-44763 is a directory traversal vulnerability. CVE-2026-44764 and CVE-2026-44765 are vulnerabilities involving missing permission checks.
- SAP Business AI Platform (Approuter): CVE-2026-58230 in versions prior to 23.0.0 Is a multiple vulnerability.
- SAP Commerce Cloud (Data Hub Adapter): CVE-2026-58231 in COM_CLOUD 2211 and 2211-JDK21 is an arbitrary code execution vulnerability caused by improper authorization.
- SAP ABAP Developer Tools: CVE-2026-58243 in SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920’s CVE-2026-58243 is a privilege escalation vulnerability.
- SAP BusinessObjects Business Intelligence Platform (Central Management Server): CVE-2026-58243 in SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920, and ENTERPRISE 430, 2025, 2027: CVE-2026-66763 is a credential exposure vulnerability.
Recommended Action
A security patch has been released; users should update to the latest version of the Vulnerability Patch following the instructions on the reference site.