Visualização normal

Hoje — 8 de Setembro de 2026Cyber Security News

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

8 de Setembro de 2026, 08:19

SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note.

The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products.

The most severe issue is CVE-2026-44756, a critical memory corruption vulnerability in SAP Extended Passport Processing, tracked under SAP Note 3747649. It carries a CVSS score of 10.0, the highest possible severity rating.

The flaw affects multiple SAP kernel and Web Dispatcher versions, including KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and 9.16 through 9.20.

An unauthenticated remote attacker could potentially exploit the memory corruption flaw to compromise confidentiality, integrity, and availability. Organizations using affected SAP kernel components should treat this update as an emergency patching priority.

Another critical vulnerability, CVE-2026-58240, affects SAP NetWeaver Message Server. SAP Note 3759472 addresses a missing authentication check with a CVSS score of 9.8. The issue affects KERNEL versions 9.16, 9.18, 9.19, and 9.20.

Successful exploitation could allow an attacker without valid credentials to access or interact with exposed services, creating a serious risk to SAP environments.

SAP Security Updates September 2026

SAP also fixed CVE-2026-76969, a critical credential disclosure vulnerability in multitenant applications using the SAP Cloud Application Programming Model library sap/cds-mtxs.

The flaw has a CVSS score of 9.4 and affects versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators should update affected dependencies quickly, especially where they handle tenant data and application credentials.

A fourth critical issue, CVE-2026-66768, impacts SAP GUI for Java in SAP NetWeaver. The improper access control vulnerability, fixed by SAP Note 3781729, has a CVSS score of 9.0. It affects BC-FES-JAV 8.10 and could allow a low-privileged attacker to gain unauthorized access after user interaction.

The September release also includes high-severity fixes, including CVE-2026-76958, an 8.5-rated XXE flaw in SAP Integration Suite Trading Partner Management that could expose sensitive files, enable server-side requests, or disrupt XML processing.

SAP patched insecure deserialization in SAP NetWeaver Business Client, memory corruption in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection in SAP Commerce Cloud Search and Navigation.

The company also released an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools originally addressed during the August 2026 Patch Day.

SAP NoteCVEVulnerabilityAffected product/versionsPriority
3747649CVE-2026-44756Memory corruptionSAP Extended Passport (EPP) Processing
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; WEBDISP: 9.16, 9.18, 9.19, 9.20; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
Critical
3759472CVE-2026-58240Missing authentication checkSAP NetWeaver Message Server
KERNEL: 9.16, 9.18, 9.19, 9.20
Critical
3798315CVE-2026-76969Credential disclosure in multitenant CAP applicationsSAP CAP library sap/cds-mtxs
Versions: ≤1.18.3, ≤2.7.6, ≤3.9.6, ≤4.0.2
Critical
3781729CVE-2026-66768Improper access controlSAP NetWeaver SAP GUI for Java
BC-FES-JAV: 8.10
Critical
3772411CVE-2026-58243Privilege escalation — updated August noteSAP ABAP Developer Tools
SAP_BASIS: 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920
High
3792978CVE-2026-76958XML External Entity (XXE)SAP Integration Suite
Cloud Integration – Trading Partner Management V2: 2.9.2; B2B Integration Factory – Cloud Integration – Trading Partner Management: 1.10.0
High
3784138CVE-2026-76967Insecure deserializationSAP NetWeaver Business Client
BC-WD-CLT-BUS: 8.00, 8.10
High
3757002CVE-2026-66767Memory corruptionSAP NetWeaver AS for ABAP and ABAP Platform
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
High
3791068CVE-2026-2332CRLF injection through Jetty componentsSAP Commerce Cloud Search and Navigation
COM_CLOUD: 2211, 2211-JDK21
High
3750721CVE-2026-76968Information disclosureSAP Web Dispatcher, Internet Communication Manager, and SAP Content Server
KRNL64NUC: 7.22, 7.22EXT; KRNL64UC: 7.22, 7.22EXT, 7.53; WEBDISP: 7.22_EXT, 7.53, 7.54, 7.77, 7.93, 9.16; CONTSERV: 7.53, 7.54; KERNEL: 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19, 9.20
Medium
3756450CVE-2026-44766SQL injectionSAP S/4HANA Intercompany Matching and Reconciliation
SAPSCORE: 136; S4CORE: 104, 105, 106, 107, 108, 109
Medium
3786489CVE-2026-76971Server-Side Request Forgery (SSRF)SAP Manufacturing Integration and Intelligence
XMII: 15.4, 15.5
Medium
3787345CVE-2026-34477Security misconfiguration due to Apache Log4jSAP Commerce Cloud Search and Navigation
COM_CLOUD: 2211, 2211-JDK21
Medium
3783189CVE-2026-76977ClickjackingSAPUI5 Frame Options Allowlist
SAP_UI: 750, 754, 755, 756, 757, 758, 816; UI_700: 200
Medium
3365276CVE-2026-76960Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
S4CORE: 105, 106, 107
Medium
3371336CVE-2026-76961Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
S4CORE: 108
Medium
3365311CVE-2026-76959Cross-Site Request Forgery (CSRF)SAP S/4HANA Finance for Advanced Payment Management
UIAPFI70: 800, 900, 901, 902
Medium
3657599CVE-2026-76962Missing authorization checkSAP S/4HANA Manage Bank Chains app
S4CORE: 107, 108, 109
Medium
3772838CVE-2026-76963Missing authorization checkSAP NetWeaver and ABAP Platform
SAP_BASIS: 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 758
Medium
3736494CVE-2026-58234Denial of serviceSAP Process Integration SOAP Adapter
MESSAGING: 7.50; SAP_XIAF: 7.50
Low

Medium-severity fixes cover SQL injection, server-side request forgery, clickjacking, cross-site request forgery, information disclosure, authorization bypass, and Apache Log4j-related security misconfiguration issues. SAP also patched a low-severity denial-of-service flaw in the SAP Process Integration SOAP Adapter.

SAP administrators should review all relevant security notes in the SAP Support Portal, map them to deployed product versions, test patches under change-control procedures, and apply the fixes as soon as possible.

Internet-facing SAP services, NetWeaver Message Server instances, cloud application dependencies, and systems processing sensitive business data should receive priority attention.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

The post SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport appeared first on Cyber Security News.

❌
❌