SAP's August 2026 Patch Day delivered 28 new Security Notes, addressing a total of 12 critical and high-priority vulnerabilities. This surpasses July's count of 10, making it the largest combined number of critical and high-priority vulnerabilities in any SAP Patch Day of 2026 so far.
Among the most notable fixes is a critical vulnerability in SAP Manufacturing Integration and Intelligence (MII), which could allow an attacker to compromise the system. SAP has assigned a CVSS score of 9.6 to this issue, indicating a severe risk.
Other high-priority vulnerabilities were fixed in SAP NetWeaver, SAP BusinessObjects, and SAP S/4HANA, among others. SAP recommends that customers apply the patches as soon as possible to mitigate potential security risks.
Security experts advise organizations to prioritize the MII patch due to its critical nature and the potential for exploitation. The full list of Security Notes is available on the SAP Support Portal.