SAP Security Updates September 2026: Critical Flaws in NetWeaver, Extended Passport, and CAP Addressed
SAP's September 2026 Security Patch Day addresses 19 vulnerabilities, including critical flaws in NetWeaver, Extended Passport Processing, and Cloud Application Programming Model.

SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note. These patches address a range of vulnerabilities across critical SAP enterprise products, including SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model (CAP), SAP S/4HANA, SAP Integration Suite, and SAP Commerce Cloud.
The most severe issue highlighted is CVE-2026-44756, a critical memory corruption vulnerability found in SAP Extended Passport Processing. This flaw, detailed in SAP Note 3747649, carries a maximum CVSS score of 10.0. It affects multiple SAP kernel and Web Dispatcher versions, including KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, and versions 9.16 through 9.20. An unauthenticated remote attacker could exploit this memory corruption to compromise the confidentiality, integrity, and availability of affected systems, making it an emergency patching priority for organizations.
Another critical vulnerability, CVE-2026-58240, impacts SAP NetWeaver Message Server. Addressed by SAP Note 3759472, this missing authentication check vulnerability has a CVSS score of 9.8. It affects KERNEL versions 9.16, 9.18, 9.19, and 9.20. Successful exploitation could allow an attacker without valid credentials to gain unauthorized access to or interact with exposed services, posing a significant risk to SAP environments.
SAP also fixed CVE-2026-76969, a critical credential disclosure vulnerability affecting multitenant applications built using the SAP Cloud Application Programming Model library, specifically sap/cds-mtxs. With a CVSS score of 9.4, this flaw impacts versions up to 1.18.3, 2.7.6, 3.9.6, and 4.0.2. Developers and cloud administrators are urged to update affected dependencies promptly, especially those handling sensitive tenant data and application credentials.
A fourth critical issue, CVE-2026-66768, affects SAP GUI for Java within SAP NetWeaver. This improper access control vulnerability, documented in SAP Note 3781729, has a CVSS score of 9.0. It impacts BC-FES-JAV version 8.10 and could allow a low-privileged attacker to achieve unauthorized access after some form of user interaction.
The September release also includes several high-severity fixes. Among these is CVE-2026-76958, an 8.5-rated XML External Entity (XXE) flaw in SAP Integration Suite Trading Partner Management, which could lead to the exposure of sensitive files or enable server-side requests. Additionally, SAP patched insecure deserialization vulnerabilities in SAP NetWeaver Business Client, memory corruption issues in SAP NetWeaver Application Server for ABAP and ABAP Platform, and CRLF injection vulnerabilities in SAP Commerce Cloud Search and Navigation.
Furthermore, SAP has released an update for CVE-2026-58243, a high-severity privilege escalation flaw in SAP ABAP Developer Tools that was initially addressed during the August 2026 Patch Day. This update reinforces the ongoing need for vigilance and timely patching of SAP systems.
The patch day also includes medium and low-severity fixes, addressing issues such as SQL injection, server-side request forgery (SSRF), clickjacking, cross-site request forgery (CSRF), missing authorization checks, and denial-of-service vulnerabilities across various SAP products. Organizations utilizing SAP solutions should consult the detailed SAP Notes for each vulnerability to assess their specific exposure and apply the necessary patches.
Given the critical nature and high CVSS scores of several vulnerabilities, particularly CVE-2026-44756 and CVE-2026-58240, SAP customers are strongly advised to prioritize these updates to mitigate the risk of exploitation and protect their sensitive enterprise data and systems.