August 2026 Patch Tuesday3765948Normal patch window

SAP · 3765948

Linked CVE review

Assess and apply SAP security advisory 3765948

Linked CVEs
1
Confirmed exploited
0
PoC or lab evidence
0
Maximum CVSS
9.9
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
1 of 1 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-44772 Critical technical severity
Code Injection vulnerability in SAP Manufacturing Integration and Intelligence

SAP lists CVE-2026-44772 in public Security Patch Day note 3765948. The detailed security note and exact fix may require SAP support access.

9.9 · CVSS 3.0 · CriticalSource: Authoritative vendor bulletinNo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: UnavailableForecast date unavailableNot availableWithin 72 hoursSAP lists this CVE as Critical in a public Patch Day bulletin. Verify applicability and the exact fix before action.Awaiting fix. SAP announced a security note, but the exact applicable fixed release is not verified from public evidence.