Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
SAP Patches Critical Flaws in NetWeaver, Cloud, and Extended Passport
September 8, 2026
Panzer Ransomware Targets Italian Firms with ESXi-Ready RaaS
September 8, 2026
US Offers $10M Reward for Iran IRGC Cyber Chief Linked to Critical Infrastructure Attacks
September 8, 2026
Home/CyberSecurity News/SAP Patches Critical Flaws in NetWeaver, Cloud, and Extended Passport
CyberSecurity News

SAP Patches Critical Flaws in NetWeaver, Cloud, and Extended Passport

Key Takeaways SAP’s September 2026 Patch Day addresses 19 new security vulnerabilities and updates one existing note. Four critical flaws, some with CVSS scores up to 10.0, impact SAP...

David kimber
David kimber
September 8, 2026 3 Min Read
2 0

Key Takeaways

  • SAP’s September 2026 Patch Day addresses 19 new security vulnerabilities and updates one existing note.
  • Four critical flaws, some with CVSS scores up to 10.0, impact SAP NetWeaver, Extended Passport Processing, and Cloud Application Programming Model.
  • Affected products span critical enterprise systems including SAP S/4HANA, SAP Integration Suite, and SAP Commerce Cloud.
  • Immediate patching is strongly recommended for organizations utilizing affected SAP kernel components and other exposed services.

SAP has released its critical security updates for September 2026, including 19 new security notes and an important revision to a previously issued patch. These updates address a range of vulnerabilities across key SAP products, with several carrying the highest possible severity ratings.

Table Of Content

  • Key Takeaways
  • Critical Vulnerabilities Demand Immediate Attention
  • Broader Fixes and Updated Notes
  • What You Should Do

The patches target various components, including SAP NetWeaver, SAP Extended Passport Processing, the SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, and SAP Commerce Cloud, among others.

Critical Vulnerabilities Demand Immediate Attention

The most pressing vulnerability, identified as CVE-2026-44756 (SAP Note 3747649), is a critical memory corruption flaw within SAP Extended Passport Processing. This vulnerability has been assigned a CVSS score of 10.0, indicating maximum severity.

The flaw impacts numerous SAP kernel and Web Dispatcher versions, specifically KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and versions 9.16 through 9.20. Exploitation by an unauthenticated remote attacker could lead to a complete compromise of confidentiality, integrity, and availability. SAP advises all organizations running affected kernel components to prioritize this update as an emergency.

Another severe issue, CVE-2026-58240, involves a missing authentication check in the SAP NetWeaver Message Server. Tracked by SAP Note 3759472, this vulnerability holds a CVSS score of 9.8. It affects KERNEL versions 9.16, 9.18, 9.19, and 9.20. Successful exploitation could grant unauthorized attackers access to critical services, posing a significant risk to the integrity of SAP environments.

A third critical vulnerability, CVE-2026-76969, addresses a credential disclosure flaw in multitenant applications leveraging the SAP Cloud Application Programming Model library sap/cds-mtxs. This issue has a CVSS score of 9.4 and affects versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators are urged to update these dependencies promptly, particularly in systems handling tenant data and application credentials.

Finally, CVE-2026-66768, with a CVSS score of 9.0, is an improper access control vulnerability in SAP GUI for Java within SAP NetWeaver, documented under SAP Note 3781729. This flaw affects BC-FES-JAV 8.10 and could enable a low-privileged attacker to gain unauthorized access following user interaction.

Broader Fixes and Updated Notes

Beyond the critical issues, the September release also includes high-severity fixes. These include CVE-2026-76958, an XML External Entity (XXE) flaw rated 8.5 in SAP Integration Suite Trading Partner Management. This vulnerability could lead to sensitive file exposure, server-side request forgery, or XML processing disruption.

Other significant fixes address insecure deserialization in SAP NetWeaver Business Client, memory corruption in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection in SAP Commerce Cloud Search and Navigation.

SAP also provided an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools, which was initially patched during the August 2026 Patch Day.

Medium-severity vulnerabilities patched include SQL injection, server-side request forgery (SSRF), clickjacking, cross-site request forgery (CSRF), information disclosure, authorization bypasses, and security misconfigurations linked to Apache Log4j. A low-severity denial-of-service vulnerability in the SAP Process Integration SOAP Adapter was also addressed.

What You Should Do

  • Review SAP Security Notes: Immediately consult the SAP Support Portal for all relevant security notes for September 2026.
  • Prioritize Critical Patches: Apply updates for CVE-2026-44756 (SAP Extended Passport Processing) and CVE-2026-58240 (SAP NetWeaver Message Server) with extreme urgency, especially for internet-facing systems or those processing sensitive data.
  • Update Cloud Application Dependencies: Developers and cloud administrators should promptly update the sap/cds-mtxs library to mitigate CVE-2026-76969.
  • Test and Deploy: Follow established change-control procedures to test patches thoroughly before deploying them to production environments.
  • Assess Exposure: Identify all SAP systems, particularly those exposed to the internet or handling critical business operations, and ensure they receive priority patching.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Panzer Ransomware Targets Italian Firms with ESXi-Ready RaaS

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
AI Customer Service Bots Vulnerable to Security Code Theft
September 8, 2026
Critical Flaw in HashiCorp Terraform Registry Lets Attackers Steal Cloud Credentials
September 8, 2026
Top 10 Web Application Firewall Solutions for 2026
September 8, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us