SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note.
The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products.
The most severe issue is CVE-2026-44756, a critical memory corruption vulnerability in SAP Extended Passport Processing, tracked under SAP Note 3747649. It carries a CVSS score of 10.0, the highest possible severity rating.
The flaw affects multiple SAP kernel and Web Dispatcher versions, including KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and 9.16 through 9.20.
An unauthenticated remote attacker could potentially exploit the memory corruption flaw to compromise confidentiality, integrity, and availability. Organizations using affected SAP kernel components should treat this update as an emergency patching priority.
Another critical vulnerability, CVE-2026-58240, affects SAP NetWeaver Message Server. SAP Note 3759472 addresses a missing authentication check with a CVSS score of 9.8. The issue affects KERNEL versions 9.16, 9.18, 9.19, and 9.20.
Successful exploitation could allow an attacker without valid credentials to access or interact with exposed services, creating a serious risk to SAP environments.
SAP Security Updates September 2026
SAP also fixed CVE-2026-76969, a critical credential disclosure vulnerability in multitenant applications using the SAP Cloud Application Programming Model library sap/cds-mtxs.
The flaw has a CVSS score of 9.4 and affects versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators should update affected dependencies quickly, especially where they handle tenant data and application credentials.
A fourth critical issue, CVE-2026-66768, impacts SAP GUI for Java in SAP NetWeaver. The improper access control vulnerability, fixed by SAP Note 3781729, has a CVSS score of 9.0. It affects BC-FES-JAV 8.10 and could allow a low-privileged attacker to gain unauthorized access after user interaction.
The September release also includes high-severity fixes, including CVE-2026-76958, an 8.5-rated XXE flaw in SAP Integration Suite Trading Partner Management that could expose sensitive files, enable server-side requests, or disrupt XML processing.
SAP patched insecure deserialization in SAP NetWeaver Business Client, memory corruption in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection in SAP Commerce Cloud Search and Navigation.
The company also released an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools originally addressed during the August 2026 Patch Day.
| SAP Note | CVE | Vulnerability | Affected product/versions | Priority |
|---|---|---|---|---|
| 3747649 | CVE-2026-44756 | Memory corruption | SAP Extended Passport (EPP) Processing KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; WEBDISP: 9.16, 9.18, 9.19, 9.20; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20 |
Critical |
| 3759472 | CVE-2026-58240 | Missing authentication check | SAP NetWeaver Message Server KERNEL: 9.16, 9.18, 9.19, 9.20 |
Critical |
| 3798315 | CVE-2026-76969 | Credential disclosure in multitenant CAP applications | SAP CAP library sap/cds-mtxsVersions: ≤1.18.3, ≤2.7.6, ≤3.9.6, ≤4.0.2 |
Critical |
| 3781729 | CVE-2026-66768 | Improper access control | SAP NetWeaver SAP GUI for Java BC-FES-JAV: 8.10 |
Critical |
| 3772411 | CVE-2026-58243 | Privilege escalation — updated August note | SAP ABAP Developer Tools SAP_BASIS: 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920 |
High |
| 3792978 | CVE-2026-76958 | XML External Entity (XXE) | SAP Integration Suite Cloud Integration – Trading Partner Management V2: 2.9.2; B2B Integration Factory – Cloud Integration – Trading Partner Management: 1.10.0 |
High |
| 3784138 | CVE-2026-76967 | Insecure deserialization | SAP NetWeaver Business Client BC-WD-CLT-BUS: 8.00, 8.10 |
High |
| 3757002 | CVE-2026-66767 | Memory corruption | SAP NetWeaver AS for ABAP and ABAP Platform KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20 |
High |
| 3791068 | CVE-2026-2332 | CRLF injection through Jetty components | SAP Commerce Cloud Search and Navigation COM_CLOUD: 2211, 2211-JDK21 |
High |
| 3750721 | CVE-2026-76968 | Information disclosure | SAP Web Dispatcher, Internet Communication Manager, and SAP Content Server KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53; WEBDISP: 7.22_EXT, 7.53, 7.54, 7.77, 7.93, 9.16; CONTSERV: 7.53, 7.54; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19, 9.20 |
Medium |
| 3756450 | CVE-2026-44766 | SQL injection | SAP S/4HANA Intercompany Matching and Reconciliation SAPSCORE: 136; S4CORE: 104, 105, 106, 107, 108, 109 |
Medium |
| 3786489 | CVE-2026-76971 | Server-Side Request Forgery (SSRF) | SAP Manufacturing Integration and Intelligence XMII: 15.4, 15.5 |
Medium |
| 3787345 | CVE-2026-34477 | Security misconfiguration due to Apache Log4j | SAP Commerce Cloud Search and Navigation COM_CLOUD: 2211, 2211-JDK21 |
Medium |
| 3783189 | CVE-2026-76977 | Clickjacking | SAPUI5 Frame Options Allowlist SAP_UI: 750, 754, 755, 756, 757, 758, 816; UI_700: 200 |
Medium |
| 3365276 | CVE-2026-76960 | Cross-Site Request Forgery (CSRF) | SAP S/4HANA Finance for Advanced Payment Management S4CORE: 105, 106, 107 |
Medium |
| 3371336 | CVE-2026-76961 | Cross-Site Request Forgery (CSRF) | SAP S/4HANA Finance for Advanced Payment Management S4CORE: 108 |
Medium |
| 3365311 | CVE-2026-76959 | Cross-Site Request Forgery (CSRF) | SAP S/4HANA Finance for Advanced Payment Management UIAPFI70: 800, 900, 901, 902 |
Medium |
| 3657599 | CVE-2026-76962 | Missing authorization check | SAP S/4HANA Manage Bank Chains app S4CORE: 107, 108, 109 |
Medium |
| 3772838 | CVE-2026-76963 | Missing authorization check | SAP NetWeaver and ABAP Platform SAP_BASIS: 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758 |
Medium |
| 3736494 | CVE-2026-58234 | Denial of service | SAP Process Integration SOAP Adapter MESSAGING: 7.50; SAP_XIAF: 7.50 |
Low |
Medium-severity fixes cover SQL injection, server-side request forgery, clickjacking, cross-site request forgery, information disclosure, authorization bypass, and Apache Log4j-related security misconfiguration issues. SAP also patched a low-severity denial-of-service flaw in the SAP Process Integration SOAP Adapter.
SAP administrators should review all relevant security notes in the SAP Support Portal, map them to deployed product versions, test patches under change-control procedures, and apply the fixes as soon as possible.
Internet-facing SAP services, NetWeaver Message Server instances, cloud application dependencies, and systems processing sensitive business data should receive priority attention.
Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.
The post SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport appeared first on Cyber Security News.
