Skip to content

Release roundup

SAP Security Patch Day, September 2026: four critical vulnerabilities among 19 fixes

Critical 10.0 Vendor: SAP 19 CVEs in scope Published

SAP Security Patch Day, September 2026 covers 19 CVEs: 4 critical, 4 high, 8 medium, 3 low. None exploited or in CISA KEV. Prioritise unauthenticated network-facing issues in SAP Extended Passport, NetWeaver Message Server and SAP CAP, then the remaining SAP Notes.

The release at a glance

SAP published the September 2026 Security Patch Day with 19 CVEs in scope for this review. The severity spread is four critical, four high, eight medium and three low. There are no exploited CVEs and none are listed in CISA KEV in this release.

The highest-scoring issues are CVE-2026-44756, a CVSS 10.0 memory corruption in SAP Extended Passport (EPP) Processing, and CVE-2026-58240, a CVSS 9.8 missing authentication check in SAP NetWeaver Message Server. Both are reachable over the network without credentials and have fixes available through SAP Note 3747649 and SAP Note 3759472 respectively. The remaining critical and high severity items span SAP Cloud Application Programming Model, SAP GUI for Java, SAP Integration Suite, SAP NetWeaver Business Client, SAP NetWeaver Application Server for ABAP and SAP S/4HANA.

What matters most

Eight items deserve first attention.

SAP Extended Passport (EPP) Processing — CVE-2026-44756 is a memory corruption flaw with a CVSS 10.0 score. An unauthenticated attacker can send a crafted network request with a malformed EPP header and potentially cause abnormal termination or a high impact on confidentiality, integrity and availability. It affects KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.53, 8.04, WEBDISP 9.16, 9.18 and 9.19. Fix via SAP Note 3747649.

SAP NetWeaver Message Server — CVE-2026-58240 is a missing authentication check with CVSS 9.8. An unauthenticated attacker with network access to the service could register an unauthorised component. Affected kernel versions are 9.16, 9.18, 9.19 and 9.20. Fix via SAP Note 3759472.

SAP Cloud Application Programming Model (CAP) — CVE-2026-76969 is a credential disclosure issue in the @sap/cds-mtxs NPM library, CVSS 9.4. An unauthenticated attacker could obtain credentials and tamper with tenant data in multitenant extensibility scenarios. Fix via SAP Note 3798315.

SAP GUI for Java — CVE-2026-66768 is an improper access control flaw, CVSS 9.0. A low-privileged attacker can manipulate a connected backend to trigger affected functionality and potentially execute commands on the user's machine. Affected version BC-FES-JAV 8.10. Fix via SAP Note 3781729.

SAP Integration Suite — CVE-2026-76958 is an XML External Entity (XXE) vulnerability, CVSS 8.5. A low-privileged attacker can read server file contents through crafted XML. Fix via SAP Note 3792978.

SAP NetWeaver Business Client — CVE-2026-76967 is an insecure deserialization issue, CVSS 7.8. A local low-privileged attacker can place crafted data for execution on next launch. Affected versions BC-WD-CLT-BUS 8.00 and 8.10. Fix via SAP Note 3784138.

SAP NetWeaver Application Server for ABAP and ABAP Platform — CVE-2026-66767 is a memory corruption issue, CVSS 7.7. An unauthenticated attacker can send a crafted packet to trigger reprocessing of a buffered request and possibly hijack another session under narrow timing conditions. Fix via SAP Note 3757002.

SAP S/4HANA (Manage Supply Protection) — CVE-2026-66766 is a ReDoS denial-of-service issue, CVSS 7.5. Unauthenticated crafted input can exhaust resources. Fix via SAP Note 3485073.

Patch in this order

  1. Apply SAP Note 3747649 for CVE-2026-44756 in SAP Extended Passport (EPP) Processing first. CVSS 10.0, network, pre-authentication, no user interaction.
  2. Apply SAP Note 3759472 for CVE-2026-58240 in SAP NetWeaver Message Server. CVSS 9.8, network, pre-authentication.
  3. Apply SAP Note 3798315 for CVE-2026-76969 in multitenant SAP CAP applications. CVSS 9.4, network, pre-authentication.
  4. Apply SAP Note 3781729 for CVE-2026-66768 in SAP GUI for Java. CVSS 9.0, critical but requires low privilege and user interaction.
  5. Apply SAP Note 3792978 for CVE-2026-76958 in SAP Integration Suite. CVSS 8.5, low privilege network.
  6. Then apply the remaining high-severity notes: SAP Note 3784138 for CVE-2026-76967 in SAP NetWeaver Business Client, SAP Note 3757002 for CVE-2026-66767 in SAP NetWeaver AS ABAP, and SAP Note 3485073 for CVE-2026-66766 in SAP S/4HANA Manage Supply Protection.
  7. Continue with the medium and low severity items from the release, including CVE-2026-44766 in S/4HANA Intercompany Matching and Reconciliation, CVE-2026-76968 in Web Dispatcher, Internet Communication Manager and Content Server, CVE-2026-76971 in SAP Manufacturing Integration and Intelligence, CVE-2026-76974 in SAP Fiori Launchpad, and the remaining CVEs listed in the table.

Beyond the patch

Next month, this release is more manageable if internet-facing SAP services are already identified and tracked, because the highest-scoring issues are reachable without credentials. A regular exposure review can keep those services mapped and patched. Virtual CISO Services supports that exposure management, and SAP HANA Security & Cloud Migration helps keep the wider SAP estate on a structured patch and migration path.

Every CVE in this release

CVEProductSeverity
CVE-2026-44756SAP Extended Passport (EPP) ProcessingCritical 10.0Advisory →
CVE-2026-58240SAP NetWeaver (Message Server)Critical 9.8Advisory →
CVE-2026-76969SAP Cloud Application Programming Model (CAP)Critical 9.4Advisory →
CVE-2026-66768SAP NetWeaver (SAP GUI for Java)Critical 9.0Advisory →
CVE-2026-76958SAP Integration SuiteHigh 8.5
CVE-2026-76967SAP NetWeaver Business ClientHigh 7.8
CVE-2026-66767SAP NetWeaver Application Server for ABAP and ABAP PlatformHigh 7.7
CVE-2026-66766SAP S/4HANA (Manage Supply Protection)High 7.5
CVE-2026-44766SAP S/4HANA (Intercompany Matching and Reconciliation)Medium 6.5
CVE-2026-76968SAP Web Dispatcher, Internet Communication Manager and SAP Content ServerMedium 6.5
CVE-2026-76971SAP Manufacturing Integration and IntelligenceMedium 6.5
CVE-2026-76974SAP Fiori LaunchpadMedium 5.3
CVE-2026-76959SAP S/4HANA (Finance for Advanced Payment Management)Medium 4.6
CVE-2026-76962SAP S/4HANA (Manage Bank Chains app)Medium 4.3
CVE-2026-76963SAP NetWeaver and ABAP PlatformMedium 4.3
CVE-2026-76977SAPUI5(Frame Options Allowlist)Medium 4.3
CVE-2026-76960SAP S/4HANA (Finance for Advanced Payment Management)Low 3.5
CVE-2026-76961SAP S/4HANA (Finance for Advanced Payment Management)Low 3.5
CVE-2026-58234SAP Process Integration (SOAP Adapter)Low 2.2

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.