Enterprise software maker SAP on Tuesday announced the release of 28 new security notes, two updates to previous notes, and a GitHub advisory.

Four of the notes published on SAP’s August 2026 Security Patch Day resolve critical vulnerabilities, the most severe of which is CVE-2026-58231 (CVSS score of 10/10), an improper authorization issue in SAP Commerce Cloud (Data Hub Adapter).

The bug could allow remote attackers to bypass authentication, likely leading to code execution and unauthorized access to internal components. Successful exploitation would impact the confidentiality, integrity, and availability of the application.

SAP also addressed two critical code injection flaws in Manufacturing Integration and Intelligence, tracked as CVE-2026-44772 (CVSS score of 9.9/10) and CVE-2026-44758 (CVSS score of 9.1/10).

Vulnerable servlets allow attackers to submit specially crafted input, leading to the execution of arbitrary commands on the underlying host and total infrastructure compromise. While the bugs are similar, one requires higher privileges to be exploited, application security firm Onapsis explains.