SAP Patches Critical Flaws in NetWeaver, Cloud, and Extended Passport
Key Takeaways SAP’s September 2026 Patch Day addresses 19 new security vulnerabilities and updates one existing note. Four critical flaws, some with CVSS scores up to 10.0, impact SAP...
Key Takeaways
- SAP’s September 2026 Patch Day addresses 19 new security vulnerabilities and updates one existing note.
- Four critical flaws, some with CVSS scores up to 10.0, impact SAP NetWeaver, Extended Passport Processing, and Cloud Application Programming Model.
- Affected products span critical enterprise systems including SAP S/4HANA, SAP Integration Suite, and SAP Commerce Cloud.
- Immediate patching is strongly recommended for organizations utilizing affected SAP kernel components and other exposed services.
SAP has released its critical security updates for September 2026, including 19 new security notes and an important revision to a previously issued patch. These updates address a range of vulnerabilities across key SAP products, with several carrying the highest possible severity ratings.
Table Of Content
The patches target various components, including SAP NetWeaver, SAP Extended Passport Processing, the SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, and SAP Commerce Cloud, among others.
Critical Vulnerabilities Demand Immediate Attention
The most pressing vulnerability, identified as CVE-2026-44756 (SAP Note 3747649), is a critical memory corruption flaw within SAP Extended Passport Processing. This vulnerability has been assigned a CVSS score of 10.0, indicating maximum severity.
The flaw impacts numerous SAP kernel and Web Dispatcher versions, specifically KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and versions 9.16 through 9.20. Exploitation by an unauthenticated remote attacker could lead to a complete compromise of confidentiality, integrity, and availability. SAP advises all organizations running affected kernel components to prioritize this update as an emergency.
Another severe issue, CVE-2026-58240, involves a missing authentication check in the SAP NetWeaver Message Server. Tracked by SAP Note 3759472, this vulnerability holds a CVSS score of 9.8. It affects KERNEL versions 9.16, 9.18, 9.19, and 9.20. Successful exploitation could grant unauthorized attackers access to critical services, posing a significant risk to the integrity of SAP environments.
A third critical vulnerability, CVE-2026-76969, addresses a credential disclosure flaw in multitenant applications leveraging the SAP Cloud Application Programming Model library sap/cds-mtxs. This issue has a CVSS score of 9.4 and affects versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators are urged to update these dependencies promptly, particularly in systems handling tenant data and application credentials.
Finally, CVE-2026-66768, with a CVSS score of 9.0, is an improper access control vulnerability in SAP GUI for Java within SAP NetWeaver, documented under SAP Note 3781729. This flaw affects BC-FES-JAV 8.10 and could enable a low-privileged attacker to gain unauthorized access following user interaction.
Broader Fixes and Updated Notes
Beyond the critical issues, the September release also includes high-severity fixes. These include CVE-2026-76958, an XML External Entity (XXE) flaw rated 8.5 in SAP Integration Suite Trading Partner Management. This vulnerability could lead to sensitive file exposure, server-side request forgery, or XML processing disruption.
Other significant fixes address insecure deserialization in SAP NetWeaver Business Client, memory corruption in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection in SAP Commerce Cloud Search and Navigation.
SAP also provided an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools, which was initially patched during the August 2026 Patch Day.
Medium-severity vulnerabilities patched include SQL injection, server-side request forgery (SSRF), clickjacking, cross-site request forgery (CSRF), information disclosure, authorization bypasses, and security misconfigurations linked to Apache Log4j. A low-severity denial-of-service vulnerability in the SAP Process Integration SOAP Adapter was also addressed.
What You Should Do
- Review SAP Security Notes: Immediately consult the SAP Support Portal for all relevant security notes for September 2026.
- Prioritize Critical Patches: Apply updates for CVE-2026-44756 (SAP Extended Passport Processing) and CVE-2026-58240 (SAP NetWeaver Message Server) with extreme urgency, especially for internet-facing systems or those processing sensitive data.
- Update Cloud Application Dependencies: Developers and cloud administrators should promptly update the
sap/cds-mtxslibrary to mitigate CVE-2026-76969. - Test and Deploy: Follow established change-control procedures to test patches thoroughly before deploying them to production environments.
- Assess Exposure: Identify all SAP systems, particularly those exposed to the internet or handling critical business operations, and ensure they receive priority patching.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.