Ukraine's prosecutor general Ruslan Kravchenko resigned amid a probe into officials who allegedly took bribes to protect fraudulent call centers.
Ukraine's prosecutor general Ruslan Kravchenko resigned over an anti-corruption probe into officials who allegedly took bribes since mid-2025 to protect fraudulent call centers; he has not been charged. NABU named five suspects, including senior prosecutor Serhii Kropyva, who was remanded with bail of 120 million hryvnias (about $2.7 million) on suspicion of laundering over 89 million hryvnias (roughly $2 million). The scam centers targeted victims in Ukraine and abroad; Ukrainian authorities reported shutting about 340 call centers over the past year, including 94 in a single week during a nationwide crackdown.
Onapsis warns over 10,000 internet-facing SAP systems may be exposed to maximum-severity unauthenticated RCE flaw CVE-2026-44756 in SAP Extended Passport.
Onapsis Research Labs discovered CVE-2026-44756, a memory corruption flaw in SAP Extended Passport (EPP) processing caused by missing boundary validation during deserialization. The bug is reachable from the SAP GUI and RFC layers, is remotely exploitable without authentication by default, and could let attackers run arbitrary OS commands with SAP administrative privileges. No active exploitation was observed at publication. Onapsis also flagged critical S4GET bug CVE-2026-58240 (CVSS 9.8) in the S/4HANA Message Server, credential disclosure CVE-2026-76969 in SAP CAP, and improper access control CVE-2026-66768 in NetWeaver.
A maximum-severity (CVSS 10.0) unauthenticated RCE flaw in SAP Commerce Cloud, CVE-2026-58231, is under active exploitation days after patching.
CVE-2026-58231, rated 10.0 on CVSS, stems from insufficient authorization checks and input validation in SAP Commerce Cloud, enabling unauthenticated arbitrary code execution. Defused Cyber's honeypots detected exploitation attempts three days after the patch, and KEVIntel independently confirmed two attempts on August 14 from a US IP address. Onapsis urges customers to patch and rebuild, with an IP Filter Set offered as a temporary workaround. No actor attribution yet, though prior SAP NetWeaver flaw CVE-2025-31324 was exploited by China-nexus and criminal groups.
SAP patched a CVSS 10.0 unauthenticated RCE flaw (CVE-2026-58231) in Commerce Cloud's Data Hub Adapter, plus three critical flaws in NetWeaver and Manufacturing.
SAP's August 2026 updates fix CVE-2026-58231, a CVSS 10.0 flaw in Commerce Cloud's Data Hub Adapter where insufficient authorization checks and input validation let unauthenticated attackers execute arbitrary code. Onapsis urged customers to patch and redeploy, with an IP Filter Set on the vulnerable endpoint offered as a temporary workaround. The update also fixed CVE-2026-44772 (CVSS 9.9) and CVE-2026-44758 (CVSS 9.1), code injection flaws in Manufacturing Integration and Intelligence involving SSRF and SSTI, and CVE-2026-34265 (CVSS 9.8), an out-of-bounds write in NetWeaver ABAP's DIAG protocol parsing that can leak information or crash systems.
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking s
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.
Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer
CVE-2025-31324 is a critical (CVSS 9.8) unrestricted file upload flaw (CWE-434) in the Visual Composer Metadata Uploader component of SAP NetWeaver, which lacks proper authorization. An unauthenticated attacker can send crafted upload requests over the network to the Metadata Uploader endpoint and plant malicious executable binaries, such as webshells, on the host. Executing the uploaded files yields remote code execution with full impact on confidentiality, integrity, and availability, enabling system compromise, lateral movement, and ransomware deployment. Any organization running the affected SAP NetWeaver component is at risk, with the greatest exposure for instances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-04-29, a public PoC exists, and researchers and media report active attacks, including by Chinese-linked actors deploying Golang-based implants on Linux systems and known ransomware use, often chained with CVE-2025-42999.
Unauthenticated buffer overflow in SAP Kernel Extended Passport (EPP) processing
CVE-2026-44756 is a critical (CVSS 10.0) memory-safety flaw — a classic buffer overflow (CWE-120) — in the Extended Passport Protocol (EPP) processing library of SAP Kernel, the core runtime underlying SAP NetWeaver components (SAP's advisories tie the issue to SAP Kernel and the NetWeaver Message Server). An unauthenticated remote attacker can trigger it by sending a crafted network request containing a malformed EPP header to a system that processes EPP traffic. The malformed header causes undefined behavior and abnormal program termination, and SAP's maximum-severity rating plus vendor coverage of the flaw indicate it can enable unauthenticated remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the affected SAP Kernel/NetWeaver components — essentially typical ABAP-stack SAP deployments — is exposed until patched. No public proof-of-concept is known, the flaw is not in CISA KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile), and fixes shipped in SAP's September 2026 Security Patch Day.
· SAP Kernel (Extended Passport Protocol (EPP) processing library) · SAP NetWeaver (kernel components, including Message Server, per SAP's 2026-011 advisory)mass
Unauthenticated Component Registration Flaw in SAP NetWeaver Message Server
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components when they register with the service (CWE-308). An unauthenticated attacker with network access to the affected service can send a crafted registration request to add or impersonate an application server component. Once registered, the attacker can potentially perform unauthorized actions within the SAP application environment, resulting in a high impact on confidentiality, integrity, and availability — reflected in the critical CVSS 9.8 score. Any organization running SAP NetWeaver deployments that rely on the Message Server is affected; the source data does not specify exact affected version ranges. There is no evidence of active exploitation, no public proof-of-concept, and the issue is not in CISA KEV, with EPSS assigning only a ~0.3% 30-day exploitation probability; a fix shipped in SAP's September 2026 Security Patch Day (a release that also patched other critical flaws, including the separately reported 'OVERPASS' SAP Kernel issue).
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption.
SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.
Unauthenticated Credential Theft and Tenant Data Tampering in SAP @sap/cds-mtxs
CVE-2026-76969 is a critical flaw (CVSS 9.4) in SAP's @sap/cds-mtxs npm package, the multitenancy component of the SAP Cloud Application Programming Model (CAP), which performs insufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker who can reach the affected endpoints can send specially crafted requests that cause the service to disclose sensitive credentials. With those credentials, the attacker can replace or delete tenant data, resulting in high impact to integrity and availability and partial impact to the confidentiality of business data. Only deployments running multitenant CAP applications on @sap/cds-mtxs with extensibility enabled are affected. Exploitation has not been observed: there is no known public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.
· SAP @sap/cds-mtxs npm library (CAP multitenancy service; exploitable when used in multitenant CAP applications with extensibniche
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating system, resulting in high impact on confidentiality, integrity, and availability of the application.
Trust Level Policy Bypass Enables RCE in SAP GUI for Java
SAP GUI for Java (CWE-807) fails to correctly enforce its trust level policy when certain functions are invoked from a connected backend system, meaning the client relies on untrusted backend input when making security decisions. To exploit it, an attacker needs low-privileged access to a connected backend (for example, a compromised or malicious SAP backend) and must manipulate that backend to trigger the affected functionality, which also requires interaction from the logged-in user (CVSS UI:R). Successful exploitation yields arbitrary command execution on the victim's workstation, with the changed-scope vector (S:C) allowing a backend-level foothold to break out onto the end-user machine and seriously impacting its confidentiality, integrity, and availability. Anyone running SAP GUI for Java to connect to SAP backends is exposed, particularly in scenarios where less-trusted or low-privileged users can influence the backend their colleagues connect to. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no in-the-wild exploitation is currently known; a fix shipped as part of SAP's September 2026 security patch day.
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.