SAP patches OVERPASS, a CVSS 10 kernel bug that lets unauthenticated attackers run commands on SAP hosts.
SAP's August update fixes a CVSS 10.0 hole letting unauthenticated attackers run code in Commerce Cloud.