{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/manufacturing-integration-and-intelligence-mii/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-34265"},{"cvss":9.1,"id":"CVE-2026-44758"},{"cvss":7.6,"id":"CVE-2026-44763"},{"cvss":7.3,"id":"CVE-2026-44764"},{"cvss":7.3,"id":"CVE-2026-44765"},{"cvss":7,"id":"CVE-2026-58230"},{"cvss":8.8,"id":"CVE-2026-58243"},{"cvss":7.9,"id":"CVE-2026-66763"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Manufacturing Integration and Intelligence (MII)","Manufacturing Integration and Intelligence","Approuter","ABAP Development Tools","NetWeaver AS ABAP","SAP BusinessObjects Business Intelligence Platform"],"_cs_severities":["high"],"_cs_tags":["roundup"],"_cs_type":"threat","_cs_vendors":["SAP"],"content_html":"\u003cp\u003eThis roundup covers 7 SAP security vulnerabilities. CVSS base scores range from 7.0 to 9.8. None are reported as actively exploited at the time of release. The issues affect ABAP Development Tools, Approuter, Manufacturing Integration and Intelligence, NetWeaver Application Server ABAP.\u003c/p\u003e\n\u003ch2 id=\"summary\"\u003eSummary\u003c/h2\u003e\n\u003ctable\u003e\n\t\u003cthead\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003cth\u003eCVE\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eCVSS\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eProduct\u003c/th\u003e\n\t\t\t\t\t\u003cth\u003eSummary\u003c/th\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/thead\u003e\n\t\u003ctbody\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-34265\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.8\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eNetWeaver Application Server ABAP\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-34265 is a critical vulnerability in the SAP NetWeaver Application Server ABAP DIAG protocol parsing logic. An unauthenticated attacker can exploit this flaw to cause memory corruption, potentially leading to unauthorized disclosure of sensitive system information or a denial-of-service condition affecting system availability.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-44758\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e9.1\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eManufacturing Integration and Intelligence (MII)\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSAP Manufacturing Integration and Intelligence (MII) is susceptible to a command injection vulnerability due to insufficient input validation. An attacker with high-level privileges can supply crafted input that results in arbitrary operating system command execution, potentially compromising the confidentiality, integrity, and availability of the affected system.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-44763\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.6\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eManufacturing Integration and Intelligence\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSAP Manufacturing Integration and Intelligence is susceptible to a path traversal vulnerability due to insufficient validation of file paths in certain functions. A privileged attacker can use specially crafted input to write files to arbitrary locations on the host system. Successful exploitation requires a secondary interaction by a legitimate user and compromises the confidentiality, integrity, and availability of the affected system.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-44764\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.3\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eManufacturing Integration and Intelligence\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSAP Manufacturing Integration and Intelligence is vulnerable to a missing authorization check in the Cost Servlet, allowing an unauthenticated attacker to manipulate business data. By sending crafted requests with specific parameter values, an attacker can perform unauthorized read, create, modify, or delete operations, impacting the overall system confidentiality, integrity, and availability.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-44765\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.3\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eManufacturing Integration and Intelligence\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSAP Manufacturing Integration and Intelligence contains a missing authorization check vulnerability allowing unauthenticated remote attackers to interact with scheduling functions. Exploitation allows for the unauthorized retrieval, creation, modification, or deletion of application-managed scheduling data.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-58230\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e7.0\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eApprouter\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSAP Approuter contains a vulnerability where insufficient validation of token content under specific, non-default configurations allows an unauthenticated attacker to redirect sensitive credential material to an attacker-controlled destination. While exploitation requires high complexity due to prerequisite environmental conditions, successful execution leads to a high impact on confidentiality.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\t\t\u003ctr\u003e\n\t\t\t\t\t\u003ctd\u003eCVE-2026-58243\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003e8.8\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eABAP Development Tools\u003c/td\u003e\n\t\t\t\t\t\u003ctd\u003eSAP ABAP Development Tools fails to perform adequate authorization checks, enabling low-privileged users to execute unauthorized database operations against SAP NetWeaver AS ABAP. This vulnerability allows an attacker to read or modify sensitive application data and disrupt service availability, posing a high risk to confidentiality, integrity, and availability.\u003c/td\u003e\n\t\t\t\u003c/tr\u003e\n\t\u003c/tbody\u003e\n\u003c/table\u003e\n\u003ch2 id=\"cve-2026-34265\"\u003eCVE-2026-34265\u003c/h2\u003e\n\u003cp\u003eCVE-2026-34265 is a critical vulnerability in the SAP NetWeaver Application Server ABAP DIAG protocol parsing logic. An unauthenticated attacker can exploit this flaw to cause memory corruption, potentially leading to unauthorized disclosure of sensitive system information or a denial-of-service condition affecting system availability.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eNetWeaver Application Server ABAP\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-34265\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-34265\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-44758\"\u003eCVE-2026-44758\u003c/h2\u003e\n\u003cp\u003eSAP Manufacturing Integration and Intelligence (MII) is susceptible to a command injection vulnerability due to insufficient input validation. An attacker with high-level privileges can supply crafted input that results in arbitrary operating system command execution, potentially compromising the confidentiality, integrity, and availability of the affected system.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eManufacturing Integration and Intelligence (MII)\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-44758\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-44758\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-44763\"\u003eCVE-2026-44763\u003c/h2\u003e\n\u003cp\u003eSAP Manufacturing Integration and Intelligence is susceptible to a path traversal vulnerability due to insufficient validation of file paths in certain functions. A privileged attacker can use specially crafted input to write files to arbitrary locations on the host system. Successful exploitation requires a secondary interaction by a legitimate user and compromises the confidentiality, integrity, and availability of the affected system.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eManufacturing Integration and Intelligence\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-44763\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-44763\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-44764\"\u003eCVE-2026-44764\u003c/h2\u003e\n\u003cp\u003eSAP Manufacturing Integration and Intelligence is vulnerable to a missing authorization check in the Cost Servlet, allowing an unauthenticated attacker to manipulate business data. By sending crafted requests with specific parameter values, an attacker can perform unauthorized read, create, modify, or delete operations, impacting the overall system confidentiality, integrity, and availability.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eManufacturing Integration and Intelligence\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-44764\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-44764\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-44765\"\u003eCVE-2026-44765\u003c/h2\u003e\n\u003cp\u003eSAP Manufacturing Integration and Intelligence contains a missing authorization check vulnerability allowing unauthenticated remote attackers to interact with scheduling functions. Exploitation allows for the unauthorized retrieval, creation, modification, or deletion of application-managed scheduling data.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eManufacturing Integration and Intelligence\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-44765\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-44765\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-58230\"\u003eCVE-2026-58230\u003c/h2\u003e\n\u003cp\u003eSAP Approuter contains a vulnerability where insufficient validation of token content under specific, non-default configurations allows an unauthenticated attacker to redirect sensitive credential material to an attacker-controlled destination. While exploitation requires high complexity due to prerequisite environmental conditions, successful execution leads to a high impact on confidentiality.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eApprouter\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-58230\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-58230\u003c/a\u003e\u003c/p\u003e\n\u003ch2 id=\"cve-2026-58243\"\u003eCVE-2026-58243\u003c/h2\u003e\n\u003cp\u003eSAP ABAP Development Tools fails to perform adequate authorization checks, enabling low-privileged users to execute unauthorized database operations against SAP NetWeaver AS ABAP. This vulnerability allows an attacker to read or modify sensitive application data and disrupt service availability, posing a high risk to confidentiality, integrity, and availability.\u003c/p\u003e\n\u003cp\u003eAffected products:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eABAP Development Tools\u003c/li\u003e\n\u003cli\u003eNetWeaver AS ABAP\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003eSource: \u003ca href=\"https://nvd.nist.gov/vuln/detail/CVE-2026-58243\"\u003ehttps://nvd.nist.gov/vuln/detail/CVE-2026-58243\u003c/a\u003e\u003c/p\u003e\n","date_modified":"2026-08-11T01:37:58Z","date_published":"2026-08-11T01:36:23Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sap-security-updates/","summary":"Roundup of SAP security advisories published in August 2026.","title":"SAP Security Updates - August 2026","url":"https://feed.craftedsignal.io/briefs/2026-08-sap-security-updates/"}],"language":"en","title":"CraftedSignal Threat Feed - Manufacturing Integration and Intelligence (MII)","version":"https://jsonfeed.org/version/1.1"}