<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>ABAP Development Tools - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/abap-development-tools/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 11 Aug 2026 01:36:23 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/abap-development-tools/feed.xml" rel="self" type="application/rss+xml"/><item><title>SAP Security Updates - August 2026</title><link>https://feed.craftedsignal.io/briefs/2026-08-sap-security-updates/</link><pubDate>Tue, 11 Aug 2026 01:36:23 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-sap-security-updates/</guid><description>Roundup of SAP security advisories published in August 2026.</description><content:encoded><![CDATA[<p>This roundup covers 7 SAP security vulnerabilities. CVSS base scores range from 7.0 to 9.8. None are reported as actively exploited at the time of release. The issues affect ABAP Development Tools, Approuter, Manufacturing Integration and Intelligence, NetWeaver Application Server ABAP.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>CVSS</th>
					<th>Product</th>
					<th>Summary</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td>CVE-2026-34265</td>
					<td>9.8</td>
					<td>NetWeaver Application Server ABAP</td>
					<td>CVE-2026-34265 is a critical vulnerability in the SAP NetWeaver Application Server ABAP DIAG protocol parsing logic. An unauthenticated attacker can exploit this flaw to cause memory corruption, potentially leading to unauthorized disclosure of sensitive system information or a denial-of-service condition affecting system availability.</td>
			</tr>
			<tr>
					<td>CVE-2026-44758</td>
					<td>9.1</td>
					<td>Manufacturing Integration and Intelligence (MII)</td>
					<td>SAP Manufacturing Integration and Intelligence (MII) is susceptible to a command injection vulnerability due to insufficient input validation. An attacker with high-level privileges can supply crafted input that results in arbitrary operating system command execution, potentially compromising the confidentiality, integrity, and availability of the affected system.</td>
			</tr>
			<tr>
					<td>CVE-2026-44763</td>
					<td>7.6</td>
					<td>Manufacturing Integration and Intelligence</td>
					<td>SAP Manufacturing Integration and Intelligence is susceptible to a path traversal vulnerability due to insufficient validation of file paths in certain functions. A privileged attacker can use specially crafted input to write files to arbitrary locations on the host system. Successful exploitation requires a secondary interaction by a legitimate user and compromises the confidentiality, integrity, and availability of the affected system.</td>
			</tr>
			<tr>
					<td>CVE-2026-44764</td>
					<td>7.3</td>
					<td>Manufacturing Integration and Intelligence</td>
					<td>SAP Manufacturing Integration and Intelligence is vulnerable to a missing authorization check in the Cost Servlet, allowing an unauthenticated attacker to manipulate business data. By sending crafted requests with specific parameter values, an attacker can perform unauthorized read, create, modify, or delete operations, impacting the overall system confidentiality, integrity, and availability.</td>
			</tr>
			<tr>
					<td>CVE-2026-44765</td>
					<td>7.3</td>
					<td>Manufacturing Integration and Intelligence</td>
					<td>SAP Manufacturing Integration and Intelligence contains a missing authorization check vulnerability allowing unauthenticated remote attackers to interact with scheduling functions. Exploitation allows for the unauthorized retrieval, creation, modification, or deletion of application-managed scheduling data.</td>
			</tr>
			<tr>
					<td>CVE-2026-58230</td>
					<td>7.0</td>
					<td>Approuter</td>
					<td>SAP Approuter contains a vulnerability where insufficient validation of token content under specific, non-default configurations allows an unauthenticated attacker to redirect sensitive credential material to an attacker-controlled destination. While exploitation requires high complexity due to prerequisite environmental conditions, successful execution leads to a high impact on confidentiality.</td>
			</tr>
			<tr>
					<td>CVE-2026-58243</td>
					<td>8.8</td>
					<td>ABAP Development Tools</td>
					<td>SAP ABAP Development Tools fails to perform adequate authorization checks, enabling low-privileged users to execute unauthorized database operations against SAP NetWeaver AS ABAP. This vulnerability allows an attacker to read or modify sensitive application data and disrupt service availability, posing a high risk to confidentiality, integrity, and availability.</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-34265">CVE-2026-34265</h2>
<p>CVE-2026-34265 is a critical vulnerability in the SAP NetWeaver Application Server ABAP DIAG protocol parsing logic. An unauthenticated attacker can exploit this flaw to cause memory corruption, potentially leading to unauthorized disclosure of sensitive system information or a denial-of-service condition affecting system availability.</p>
<p>Affected products:</p>
<ul>
<li>NetWeaver Application Server ABAP</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34265">https://nvd.nist.gov/vuln/detail/CVE-2026-34265</a></p>
<h2 id="cve-2026-44758">CVE-2026-44758</h2>
<p>SAP Manufacturing Integration and Intelligence (MII) is susceptible to a command injection vulnerability due to insufficient input validation. An attacker with high-level privileges can supply crafted input that results in arbitrary operating system command execution, potentially compromising the confidentiality, integrity, and availability of the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Manufacturing Integration and Intelligence (MII)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44758">https://nvd.nist.gov/vuln/detail/CVE-2026-44758</a></p>
<h2 id="cve-2026-44763">CVE-2026-44763</h2>
<p>SAP Manufacturing Integration and Intelligence is susceptible to a path traversal vulnerability due to insufficient validation of file paths in certain functions. A privileged attacker can use specially crafted input to write files to arbitrary locations on the host system. Successful exploitation requires a secondary interaction by a legitimate user and compromises the confidentiality, integrity, and availability of the affected system.</p>
<p>Affected products:</p>
<ul>
<li>Manufacturing Integration and Intelligence</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44763">https://nvd.nist.gov/vuln/detail/CVE-2026-44763</a></p>
<h2 id="cve-2026-44764">CVE-2026-44764</h2>
<p>SAP Manufacturing Integration and Intelligence is vulnerable to a missing authorization check in the Cost Servlet, allowing an unauthenticated attacker to manipulate business data. By sending crafted requests with specific parameter values, an attacker can perform unauthorized read, create, modify, or delete operations, impacting the overall system confidentiality, integrity, and availability.</p>
<p>Affected products:</p>
<ul>
<li>Manufacturing Integration and Intelligence</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44764">https://nvd.nist.gov/vuln/detail/CVE-2026-44764</a></p>
<h2 id="cve-2026-44765">CVE-2026-44765</h2>
<p>SAP Manufacturing Integration and Intelligence contains a missing authorization check vulnerability allowing unauthenticated remote attackers to interact with scheduling functions. Exploitation allows for the unauthorized retrieval, creation, modification, or deletion of application-managed scheduling data.</p>
<p>Affected products:</p>
<ul>
<li>Manufacturing Integration and Intelligence</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-44765">https://nvd.nist.gov/vuln/detail/CVE-2026-44765</a></p>
<h2 id="cve-2026-58230">CVE-2026-58230</h2>
<p>SAP Approuter contains a vulnerability where insufficient validation of token content under specific, non-default configurations allows an unauthenticated attacker to redirect sensitive credential material to an attacker-controlled destination. While exploitation requires high complexity due to prerequisite environmental conditions, successful execution leads to a high impact on confidentiality.</p>
<p>Affected products:</p>
<ul>
<li>Approuter</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-58230">https://nvd.nist.gov/vuln/detail/CVE-2026-58230</a></p>
<h2 id="cve-2026-58243">CVE-2026-58243</h2>
<p>SAP ABAP Development Tools fails to perform adequate authorization checks, enabling low-privileged users to execute unauthorized database operations against SAP NetWeaver AS ABAP. This vulnerability allows an attacker to read or modify sensitive application data and disrupt service availability, posing a high risk to confidentiality, integrity, and availability.</p>
<p>Affected products:</p>
<ul>
<li>ABAP Development Tools</li>
<li>NetWeaver AS ABAP</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-58243">https://nvd.nist.gov/vuln/detail/CVE-2026-58243</a></p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>