Bottom line: CERT-Bund warns of several critical vulnerabilities as part of SAP Patch Day August 2026, which enable code execution, privilege escalation, and data disclosure, among other things.
As part of Patch Day August 2026, SAP has released updates for several vulnerabilities in its software that are classified as critical. Affected organizations should promptly review and apply the available patches.
CERT-Bund has published an updated security advisory on SAP Patch Day August 2026 under the identifier WID-SEC-2026-2746. The advisory summarizes several vulnerabilities in SAP software whose exploitation opens up a broad range of attack possibilities for attackers: execution of arbitrary code, escalation of privileges, bypassing of existing security measures, disclosure of confidential information and credentials, manipulation of data, as well as SQL injection and cross-site scripting attacks. In addition, a denial-of-service condition can be triggered in individual cases. The present summary does not name specific CVE numbers, affected product versions, or details on individual vulnerabilities; these can be found in SAP’s original publication or the full CERT-Bund advisory.
For CISOs with SAP landscapes, the breadth of the attack vectors mentioned means that a blanket risk assessment without looking at the detailed list of individual SAP notes is not sufficient. In particular, vulnerabilities that enable code execution or privilege escalation typically affect business-critical systems such as ERP, S/4HANA, or connected middleware components and can, if exploited, provide direct access to sensitive corporate data and core processes. The listed SQL injection and cross-site scripting vulnerabilities are also relevant for all SAP web applications and portals that are broadly accessible, whether externally or internally.
As a concrete next step, security officers should consult the full SAP Security Patch Day list for August 2026 as well as the associated CERT-Bund advisory (WID-SEC-2026-2746) in order to prioritize the SAP Security Notes listed there according to CVSS rating and relevance to their own system landscape. Since this is an update to an existing advisory, it is also worthwhile to compare it with previously published versions to identify newly added or changed entries.
Source: wid.cert-bund.de · Published August 17, 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.