Notes28 new, 2 updated
4 critical severity
Critical productsSAP NetWeaver
SAP BI Platform
SAP Commerce Cloud
Release dateAugust 12, 2026
(second Tuesday)
Prior patternSAP CVEs exploited
within weeks of
disclosure historically
What happened
SAP released its August 2026 Security Patch Day on August 12, 2026, the same day as Microsoft's Patch Tuesday. The release covers 28 new security notes and two updates to previously published notes. Four notes carry critical severity ratings. The critical-rated vulnerabilities affect SAP NetWeaver, the integration and application platform underpinning most SAP enterprise deployments; SAP Business Intelligence Platform, used for enterprise analytics and reporting on financial, operational, and HR data; and SAP Commerce Cloud, SAP's e-commerce and order management platform. SAP has not disclosed the full technical detail of the critical notes until customers have had time to apply patches, which is the company's standard disclosure practice. The products affected in August are broadly deployed: NetWeaver in particular is foundational to SAP ERP, S/4HANA, and the application integration layer used by large enterprises for payroll, general ledger, procurement, and supply chain functions. Business Intelligence Platform is the analytics layer that connects to those systems and is frequently used for financial reporting. The broader August release also addresses remote code execution, server-side request forgery, XML external entity injection, and authorization bypass vulnerabilities across additional SAP products.
Why it matters
SAP NetWeaver is among the most documented enterprise application exploitation targets for both nation-state and ransomware actors. CVE-2025-31324, a critical NetWeaver vulnerability from April 2025, was added to CISA KEV and exploited by Chinese state-linked actors within days of publication. Multiple SAP NetWeaver critical vulnerabilities between 2023 and 2025 were used in ransomware campaigns specifically targeting the SAP layer because access to NetWeaver gives attackers reach into the financial and HR systems running on top of it. The August release's critical notes in NetWeaver carry this prior exploitation history as context. Any organization running SAP should treat SAP Security Patch Day with the same priority discipline applied to Microsoft Patch Tuesday. SAP environments frequently lag on patching due to complex change management requirements around ERP systems, which is precisely why they are a documented target: attackers have learned that the window between SAP patch publication and enterprise adoption is measurably longer than for operating system patches.
Don't miss
August SAP patch days coincide with Patch Tuesday by convention, which means security teams are processing two major enterprise patch releases simultaneously. The operational temptation is to handle the Microsoft release first because it affects more endpoints and carries the confirmed exploitation of CVE-2026-68820. SAP patches warrant parallel attention rather than sequential processing. NetWeaver is an internet-facing component in many large enterprise configurations, and a critical SAP NetWeaver vulnerability with no remediation is a more attractive initial access target for a financially motivated actor than a Windows privilege escalation that still requires code running on the machine. SAP's Support Portal provides the specific patch instructions for each security note. Customers can access the notes through the SAP Support Portal security notes section.
Potential actions
- Access SAP's August 2026 Security Patch Day notes through the SAP Support Portal and apply the four critical-rated notes to NetWeaver, Business Intelligence Platform, and Commerce Cloud deployments. SAP patches require coordination with the application team, not just the OS patching team, because ERP system updates often involve configuration and testing steps beyond binary deployment.
- Prioritize internet-facing SAP NetWeaver components in the patching sequence. Web Dispatcher, ICM, and other externally accessible NetWeaver interfaces are the documented exploitation entry points for prior critical NetWeaver CVEs and should receive the critical-note patches first within the SAP environment.
The Sip
Four critical SAP bugs in the system running payroll and financial close, on the same day as Patch Tuesday. SAP patches take longer to apply in large enterprises, which is exactly why SAP is a documented initial access target. Do not let the Microsoft release push the SAP notes to next week.