-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Security Patch Day - September 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.
On 8th of September 2026, SAP security patch day saw the release of 19 new security notes. There is 1 update to previously released security note.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2026-44756] Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing Product - SAP Extended Passport (EPP) Processing | Critical | ||
[CVE-2026-58240] Missing Authentication check in SAP NetWeaver (Message Server) Product - SAP NetWeaver (Message Server) | Critical | ||
[CVE-2026-76969] Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) Library - sap/cds-mtxs | Critical | ||
[CVE-2026-66768] Improper Access Control in SAP NetWeaver (SAP GUI for Java) Product - SAP NetWeaver (SAP GUI for Java) | Critical | ||
Update to Security Note released on August 2026 Patch Day: [CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools Product - SAP ABAP Developer Tools | High | ||
[CVE-2026-76958] XML External Entity (XXE) Vulnerability in SAP Integration Suite Product - SAP Integration Suite | High | ||
[CVE-2026-76967] Insecure Deserialization in SAP NetWeaver Business Client Product - SAP NetWeaver Business Client | High | ||
[CVE-2026-66767] Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform Product - SAP NetWeaver Application Server for ABAP and ABAP Platform | High | ||
[CVE-2026-2332] CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) Product - SAP Commerce Cloud (Search And Navigation) | High | ||
[CVE-2026-76968] Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server Product - SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | Medium | ||
[CVE-2026-44766] SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation) Product - SAP S/4HANA (Intercompany Matching and Reconciliation) | Medium | ||
[CVE-2026-76971] Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence Product - SAP Manufacturing Integration and Intelligence | Medium | ||
[CVE-2026-34477] Security Misconfiguration vulnerability due to use of Apache Log4j in SAP Commerce Cloud (Search and Navigation) Product - SAP Commerce Cloud (Search and Navigation) | Medium | ||
[CVE-2026-76977] Clickjacking vulnerability in SAPUI5(Frame Options Allowlist) Product - SAPUI5(Frame Options Allowlist) | Medium | ||
[CVE-2026-76960] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) Product - SAP S/4HANA (Finance for Advanced Payment Management) | Medium | ||
[CVE-2026-76961] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) Product - SAP S/4HANA (Finance for Advanced Payment Management) | Medium | ||
[CVE-2026-76959] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) Product - SAP S/4HANA (Finance for Advanced Payment Management) | Medium | ||
[CVE-2026-76962] Missing Authorization check in SAP S/4HANA (Manage Bank Chains app) Product - SAP S/4HANA (Manage Bank Chains app) | Medium | ||
[CVE-2026-76963] Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform Product - SAP NetWeaver and ABAP Platform | Medium | ||
[CVE-2026-58234] Denial of Service vulnerability in SAP Process Integration (SOAP Adapter) Product - SAP Process Integration (SOAP Adapter) | Low |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.