TL;DR
On September 8, 2026, the software vendor released 19 new security notes and one update during its monthly release cycle. The September 2026 SAP Security Patch Day addresses severe vulnerabilities across Extended Passport Processing, NetWeaver, and Cloud Application Programming. Administrators must apply these updates immediately to prevent unauthorized network access and potential system compromise.
- Total: 5 CVEs
- Severity: 4 Critical · 1 High
- Actively exploited: None confirmed
- Highest severity: 10.0 (Critical · CVSSv3) — CVE-2026-44756
- Action: Apply the latest security updates now
Notable CVEs
| CVE | CVSS (CVSSv3) | Type | Status |
|---|---|---|---|
| CVE-2026-44756 | 10 | CWE-120 | Not exploited |
| CVE-2026-58240 | 9.8 | CWE-308 | Not exploited |
| CVE-2026-76969 | 9.4 | CWE-522 | Not exploited |
| CVE-2026-66768 | 9 | CWE-807 | Not exploited |
| CVE-2026-58243 | 8.8 | CWE-862 | Not exploited |
Why It Matters
Enterprise resource planning software manages mission-critical business data, financial records, and operational logistics for tens of thousands of organizations globally. A compromised application server grants threat actors unrestricted access to highly sensitive corporate information. The September 2026 SAP Security Patch Day resolves multiple flaws carrying maximum CVSS scores of 10.0 and 9.8. Currently, the software developer reports no active in-the-wild exploitation or public proof-of-concept code for these specific vulnerabilities. However, unpatched internet-facing systems remain in immediate danger.
How the Attacks Work
The most severe vulnerability, CVE-2026-44756, affects the Extended Passport Protocol library. An unauthenticated attacker transmits a malformed protocol header through a crafted network request. Consequently, this triggers a memory corruption fault resulting in undefined behavior or sudden program termination.
Simultaneously, CVE-2026-58240 impacts NetWeaver Message Server environments. The server fails to validate internal component authenticity during the registration process. This allows a remote attacker to register an unauthorized malicious component inside the application environment. Another critical flaw, CVE-2026-76969, exposes multitenant Cloud Application Programming instances to credential theft via specially crafted requests.
Affected Versions
These vulnerabilities impact multiple enterprise software installations. The Extended Passport flaw affects KRNL64NUC 7.22, KRNL64UC 7.22 to 8.04, WEBDISP 9.16 through 9.20, and KERNEL 7.22 through 9.20. The NetWeaver Message Server vulnerability exists in KERNEL versions 9.16 to 9.20. The Cloud Application Programming credential disclosure impacts the sap/cds-mtxs library across versions 1.18.3, 2.7.6, 3.9.6, and 4.0.2.
Patch and Mitigation Steps
System administrators should navigate to the official SAP security advisory to download the latest security notes immediately. Apply all updates included in this SAP Security Patch Day cycle across development, testing, and production servers. Finally, review network access logs for anomalous registration attempts against the Message Server.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!