Second Tuesday of the month, SAP publishes its security notes, and somewhere in every SAP shop a person opens the list and starts reading. August is half again as large as July: 31 items, of which 4 critical, 8 high, 17 medium and 2 low. At the top, note 3771065 (CVE-2026-58231, CVSS 10.0) - an improper authorization flaw in the Data Hub Adapter for SAP Commerce Cloud. The last note to score 10.0 came out in November 2025.
A 10.0 is the ceiling of the scale, and it is arithmetic rather than rhetoric. The vector reads network attack, no privileges required, low complexity, changed scope, and full impact on confidentiality, integrity and availability. In plain terms: if the vulnerable adapter is reachable, the attacker needs no account, needs nobody to click anything, and is not contained by the component boundary. Affected versions are COM_CLOUD 2211 and 2211-JDK21.
The short version:
1/ note 3771065 at CVSS 10.0 hits the Data Hub Adapter in Commerce Cloud, a component that by design faces inbound traffic,
2/ the theme of the month is the manufacturing layer - six notes land on SAP Manufacturing Integration and Intelligence, two of them critical, and MII is the seam between your SAP systems and the shop floor,
3/ NIS2 counts 24 hours to an early warning and 72 hours to a full incident report from detection, not from publication of the note, which is bad news rather than good news for anyone without detection,
4/ in Poland, where NIS2 is implemented through the national cybersecurity act, essential and important entities must file for registration by 3 October 2026.

What shipped on 11 August
The full list runs to 31 items: 28 new notes, one GitHub advisory and two updates to earlier notes. Below are the ones that usually decide the order of work.
| Note | CVE | CVSS | Component | What to remember |
|---|---|---|---|---|
| 3771065 | CVE-2026-58231 | 10.0 | Commerce Cloud (Data Hub Adapter) | Unauthenticated, scope changed, full compromise |
| 3765948 | CVE-2026-44772 | 9.9 | Manufacturing Integration and Intelligence | Code injection via SSRF during XSL transformations |
| 3714806 | CVE-2026-34265 | 9.8 | NetWeaver AS ABAP / ABAP Platform | Memory corruption in DIAG parsing, fixed at kernel level |
| 3758900 | CVE-2026-44758 | 9.1 | Manufacturing Integration and Intelligence | SAP removes the vulnerable servlet rather than fixing it |
| 3772411 | CVE-2026-58243 | 8.8 | ABAP Developer Tools | Privilege escalation across SAP_BASIS 750-920 |
| 3773203 | CVE-2026-42945 | 8.1 | Commerce Cloud | Flaw in bundled NGINX, requires application rebuild |
| 3756565 | CVE-2026-66763 | 7.9 | BusinessObjects BI (Central Management Server) | The patch alone is not enough, credentials must be rotated |
| 3773304 | CVE-2026-58233 | 7.6 | Change and Transport System Attach Tool | Support ended - the tool is withdrawn, copies must be deleted |
| 3786038 | CVE-2026-58230 | 7.0 | Business AI Platform (Approuter) | One note, eleven vulnerabilities |
Two things separate this month from July, which brought 20 items and topped out at 9.9. The first is volume: the batch grew by half. The second is more interesting - the component mix moved away from the ERP core. Six notes hit MII, five hit Commerce Cloud, and in six items the vulnerability did not originate in SAP code at all: NGINX, Apache Log4j Core, Bouncy Castle, OpenSSL and libcurl inside Adobe Document Services, the pyodata package from PyPI, and a library used by the transport attach tool. An organisation that tracks only kernel patch level and support packages will close less than half of what August delivered.
Reading the list is not the technical part
Reading several dozen notes takes half a day. Working out which ones apply to your versions, components and kernel patch level takes several days of someone who knows the landscape by heart. That is where the process breaks - not at installing the patch, but at deciding what to patch.
The usual pattern: someone scans the list, flags the critical items, and files the rest for review at the next maintenance window. The window comes once a quarter, so an August note rated 8 waits until November. Nobody made a bad call. Nobody had time to make any call.
August offers an unusually clean example of what such a process drops. Note 3773304 covers ctsattach, the attach tool of the enhanced Change and Transport System, and scores 7.6 - second-tier in any normal triage. Except that with the release of this note SAP stopped supporting the tool, which is no longer available. The instruction is to stop using it and delete every copy from every system; note 2473648 carries the additional detail. That is an inventory and governance task, not a technical one. No process built around the question “is the package installed” will ever close this note, because the remedy is withdrawal, not installation. And it sits in the layer through which every change travels on its way to production. One practical caveat: the August table lists this item under number 3727078, but the note for this CVE was published in July as 3773304, and that is the number to search for in SAP for Me. Note 3727078 leads somewhere else entirely - a directory traversal flaw in NetWeaver AS Java.
Note 3756565 in BusinessObjects belongs to the same category. Credentials were protected by a hard-coded cryptographic key, so applying the fix closes the exposure going forward but does not invalidate anything that may already have leaked. Without rotating credentials per SAP KBA 3763536, the system reaches a state where the patch report shows green and the risk continues.
What the regulation actually demands
NIS2, as implemented in Polish law and in force since 3 April 2026, contains no clause saying “install patches”. It requires measures proportionate to risk, and it sets deadlines: 24 hours for an early warning, 72 hours for a significant incident report, one month for the final report - all counted from detection.
That has a counter-intuitive consequence. An organisation unable to detect exploitation never formally starts the clock, and sometimes reads that silence as safety. Regulators read it the other way round: not knowing your own state is evidence of inadequate measures, not a mitigating circumstance. Fines reach EUR 10 million or 2 percent of turnover for essential entities, EUR 7 million or 1.4 percent for important ones.
It is worth noting where this month’s flaws actually sit. Manufacturing is one of the sectors in scope, and MII is precisely the layer where SAP meets the shop floor. In many organisations it has a separate owner, a separate maintenance cycle, and never appears on the list of systems covered by standard patching. Six notes in a single month, two of them critical, make a good moment to check whether that layer is in your cycle at all.
Then there is the personal data layer. If unpatched exposure leaks data out of SAP, the GDPR clock is 72 hours from becoming aware, and Article 83 allows up to EUR 20 million or 4 percent of global turnover. We covered the Polish deadlines in a separate piece on NIS2 and the register.
Check where you stand before someone else asks
SNOK KSC-CHECK is a free readiness assessment for SAP systems against NIS2 and its Polish implementation: 25 questions across 6 steps and 5 areas, 8 to 12 minutes. You get the score on screen and a PDF report by email, with a 30-day and a 12-month plan.
The five areas are event visibility, detection and response, vulnerabilities, identity and access, and evidence for audit. Today’s article touches the first three directly. Under vulnerabilities, the questions ask what your path from published note to deployed patch looks like and who owns it. Under visibility, whether the Security Audit Log is switched on for critical event classes and whether anyone actually reads it, since an enabled log on its own solves nothing. Under detection, whether SAP events reach a SIEM or a SOC, without which the 24-hour clock has nothing to start from. The evidence area carries its own weight, because the first audit of essential entities, scheduled for 3 April 2028, will assess evidence from 2026 and 2027 - the years being recorded now.
One boundary worth stating plainly: this is a self-assessment, not an audit and not a certification of compliance. It shows where the gaps are and what to close first.
Take the KSC-CHECK assessment - and if it turns out your patch process is documented, staffed and evidenced, that is the best possible outcome of this article.
How to stop starting from zero every second Tuesday
Monthly note triage is work you can do once and then automate, on one condition: the system has to know your landscape - versions, components, kernel level, installed packages.
That is what Patch Management in SecurityBridge does. Published notes are mapped automatically onto your specific systems, so instead of a list for the entire SAP world you get a list for yourself, with priority and deployment status. August makes the difference visible. An organisation with no Commerce Cloud, no MII and no BusinessObjects can defer most of this list - but it has to know that from the state of its systems rather than from assumption. The reverse case is worse: a manufacturer running MII has six items this month in a component nobody had on the list.
Patching is one layer. The second is the code you write yourself - see our piece on AI-generated ABAP, covered in SecurityBridge by Code Vulnerability Analysis. The third is real-time detection, without which the 24-hour clock has nothing to start from, which we covered in the data breach your SIEM cannot see and which maps to Threat Detection and SIEM integration. Together those three layers are what a regulator means by measures proportionate to risk.
SNOK holds SecurityBridge Polska Premier Partner status, so implementation and support run in local hours and local language.
What to do this week
1/ Check whether you run SAP Commerce Cloud with the Data Hub Adapter on COM_CLOUD 2211 or 2211-JDK21, and treat note 3771065 as today’s work rather than next window’s. In parallel, inventory every copy of ctsattach - note 3773304 is closed by removing the tool, not by installing a package. If you run manufacturing on MII, check XMII 15.4 and 15.5 against this month’s six notes.
2/ Measure how long it took you to deploy July’s critical notes. That single number says more about your process than any policy document.
3/ Take the KSC-CHECK assessment and bring the report to your next board meeting. The October deadline belongs to the board, not to IT.
If those three steps show you are short of hands or tooling, get in touch. We start with a review of the actual state, not with a quote.
