CVE-2026-44758Active Exploitation

LOWCVSS 9.1 · CRITICAL

Exploitation ongoing with high activity in latest observed window (2 mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 2 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-08-18: 2Active Exploitation · 2026-08-18: 1Technical Details · 2026-08-18: 208-18
Signal classification2 categories
Active Exploitation
150.0%
Disclosure
150.0%
Full discourse2 posts
  • ERP Focus@ERPfocus
    Disclosure

    6 of August's SAP vulnerabilities landed in 1 product. SAP Manufacturing Integration and Intelligence took 2 critical, 3 high-priority and 1 medium-severity note, including CVE-2026-44772 at CVSS 9.9 and CVE-2026-44758 at CVSS 9.1.

    Post summary

    The text announces six SAP vulnerabilities affecting the Manufacturing Integration and Intelligence product, listing CVE IDs, CVSS scores, and severity classifications.

    1000062
    4.0K followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: multiple critical code injection, out-of-bounds write in #SAP #commercecloud #netweaver #MII CVE-2026-58231, CVE-2026-44772, CVE-2026-34265 & CVE-2026-44758 CVSS: 10-9.1 The first one is actively exploited #Patch #Patch #Patch

    Post summary

    Multiple critical SAP vulnerabilities with high CVSS scores are actively exploited, but no PoC, exploit code, or patch details are disclosed.

    00000294
    7.2K followersView on X

Explore more