July had already produced the largest combined number of critical and high-priority vulnerabilities of any SAP Patch Day in 2026. August surpassed that total, with 12 compared to the 10 in July. SAP’s August 2026 Patch Day delivered 28 new Security Notes and one GitHub security advisory, along with two updates.
The volume adds pressure to a problem SAP customers were already reporting. SAPinsider’s recently published Cybersecurity Threats and Challenges to SAP Systems 2026 benchmark found that keeping up with SAP Security Notes, patches, and updates remains the biggest challenge for security leaders and their teams.
August shows how this is playing out in practice. Teams have more vulnerabilities to assess, the highest-severity issues present very different attack conditions, and remediation is distributed across multiple technical owners. The month’s risks stretch from an unauthenticated CVSS 10.0 flaw in SAP Commerce Cloud to six vulnerabilities affecting SAP Manufacturing Integration and Intelligence (MII).
MII Makes Manufacturing the Defining August Risk Cluster
SAP MII stands out in August because six Security Notes affect the platform: two critical, three high-priority, and one medium-priority. The vulnerabilities span code injection, directory traversal and missing authorization checks, creating several different paths to compromise around the same manufacturing integration layer.
Layer Seven Security focused on how SAP is closing the two critical MII attack paths.
SAP Manufacturing Integration and Intelligence code injection, rated CVSS 9.9, led SAP to introduce Secure Transformer and Allowed Hosts controls that restrict where XSL content can come from. A second SAP Manufacturing Integration and Intelligence code-injection vulnerability, rated 9.1, prompted SAP to remove the vulnerable IllumXSLTServlet and direct customers to an alternative XSL transformation action.
The different responses show that August’s MII remediation involves configuration changes and, in one case, replacing vulnerable functionality altogether.
Jonathan Stross, Senior Product Manager, Cybersecurity R&I at Pathlock, took a broader view of the six findings. In his August analysis, he wrote that “manufacturing application security is now a front-line SAP concern.”
Stross advised customers to treat the MII findings as a coordinated remediation effort, rather than six separate tickets, because the issues affect several different parts of how MII handles data, files, scheduling, costing, and user access.
Gert-Jan Koster, SAP Security specialist at SecurityBridge, connected the August MII vulnerabilities more directly to manufacturing operations.
Koster noted that MII links shop-floor systems and equipment with SAP ERP and SAP S/4HANA, which can extend the impact of a compromise beyond the application itself. “After the patch is applied, system properties need to be maintained,” stressing that patching the CVSS 9.9 code-injection flaw does not finish the work.
The analysis shows why manufacturers need to treat the August MII issues as more than an application-security problem. A compromise could disrupt production data flows, plant integrations, and the business processes that depend on them.
August Shows Why Remediation Does Not End With the Patch
The August release shows why patching is becoming a broader operational task for SAP teams. Several of the month’s vulnerabilities require work beyond installing a software correction, whether that means changing configuration or reviewing access.
The vendor analyses point to the same broader problem: some August fixes require work after the patch itself. Layer Seven highlighted changes to how affected components are configured or used, while Pathlock argued that SAP vulnerability management is “not a monthly note-import exercise.” SecurityBridge added that some corrections can also affect system availability, turning remediation into a planning issue as well as a technical one
The analyses point to a larger shift in how SAP customers need to think about Patch Day. Effective remediation starts with identifying the affected system and assigning the right owners. Teams then need to complete the required work and verify that the exposure has been removed. That makes ownership and verification as important as patching speed.
What This Means for ERP Insiders
Patch volume is becoming a capacity problem. August suggests SAP security teams may face a growing workload problem. Organizations will need clearer ownership and prioritization rules to prevent high-risk fixes from competing for the same limited resources.
Manufacturing integrations deserve separate security treatment. The concentration of MII flaws shows how integration layers can widen the consequences of an application vulnerability. Manufacturers may need to treat connections between plant systems and ERP as shared security dependencies.
CVSS alone cannot set remediation order. August’s highest-severity flaws differ significantly in how attackers can reach them and what systems they affect. Remediation priorities therefore need to reflect exposure, business importance, and operational disruption alongside the numerical severity score.
This article was first published by SAPinsider on August 12, 2026.




