CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-44772: Code Injection in SAP Manufacturing Integration and Intelligence

August 12, 2026

A critical code injection vulnerability in SAP Manufacturing Integration and Intelligence (CVSS 9.9) allows a low-privileged attacker to submit crafted input, causing the application to fetch and process attacker-controlled content from an external source, leading to arbitrary command execution. The patch requires maintaining a 'Secure Transformer' property with allowed hosts for XSL files.