SAP Security Patch Day - September 2026

This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.

On 8th of September 2026, SAP security patch day saw the release of 19 new security notes. There is 1 update to previously released security note.

Note#

Title

Priority

CVSS

3747649

[CVE-2026-44756] Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing

Product - SAP Extended Passport (EPP) Processing
Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20

Critical

10.0

3759472

[CVE-2026-58240] Missing Authentication check in SAP NetWeaver (Message Server)

Product - SAP NetWeaver (Message Server)
Version(s) - KERNEL 9.16, 9.18, 9.19, 9.20

Critical

9.8

3798315

[CVE-2026-76969] Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)

Library - sap/cds-mtxs
Version(s) <=1.18.3, <=2.7.6, <=3.9.6, <=4.0.2

Critical

9.4

3781729

[CVE-2026-66768] Improper Access Control in SAP NetWeaver (SAP GUI for Java)

Product - SAP NetWeaver (SAP GUI for Java)
Version(s) - BC-FES-JAV 8.10

Critical

9.0

3772411

Update to Security Note released on August 2026 Patch Day:

[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools

Product - SAP ABAP Developer Tools
Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920

High

8.8

3792978

[CVE-2026-76958] XML External Entity (XXE) Vulnerability in SAP Integration Suite

Product - SAP Integration Suite
Version(s): Cloud Integration - Trading Partner Management V2 2.9.2, B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0

High

8.5

3784138

[CVE-2026-76967] Insecure Deserialization in SAP NetWeaver Business Client

Product - SAP NetWeaver Business Client
Version(s) - BC-WD-CLT-BUS 8.00, 8.10

High

7.8

3757002

[CVE-2026-66767] Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform

Product - SAP NetWeaver Application Server for ABAP and ABAP Platform
Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20

High

7.7

3791068

[CVE-2026-2332] CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation)

Product - SAP Commerce Cloud (Search And Navigation)
Version(s) - COM_CLOUD 2211, 2211-JDK21

High

7.4

3750721

[CVE-2026-76968] Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server

Product - SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, WEBDISP 7.22_EXT, 7.53, 7.54, 7.77, 7.93, 9.16, CONTSERV 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19, 9.20

Medium

6.5

3756450

[CVE-2026-44766] SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)

Product - SAP S/4HANA (Intercompany Matching and Reconciliation)
Version(s) - SAPSCORE 136, S4CORE 104, 105, 106, 107, 108, 109

Medium

6.5

3786489

[CVE-2026-76971] Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence

Product - SAP Manufacturing Integration and Intelligence
Version(s) - XMII 15.4, 15.5

Medium

6.5

3787345

[CVE-2026-34477] Security Misconfiguration vulnerability due to use of Apache Log4j in SAP Commerce Cloud (Search and Navigation)

Product - SAP Commerce Cloud (Search and Navigation)
Version(s) - COM_CLOUD 2211, 2211-JDK21

Medium

5.9

3783189

[CVE-2026-76977] Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)

Product - SAPUI5(Frame Options Allowlist)
Version(s) - SAP_UI 750, 754, 755, 756, 757, 758, 816, UI_700 200

Medium

4.3

3365276

[CVE-2026-76960] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)

Product - SAP S/4HANA (Finance for Advanced Payment Management)
Version(s) - S4CORE 105, 106, 107

Medium

4.3

3371336

[CVE-2026-76961] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)

Product - SAP S/4HANA (Finance for Advanced Payment Management)
Version(s) - S4CORE 108

Medium

4.3

3365311

[CVE-2026-76959] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)

Product - SAP S/4HANA (Finance for Advanced Payment Management)
Version(s) - UIAPFI70 800, 900, 901, 902

Medium

4.3

3657599

[CVE-2026-76962] Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)

Product - SAP S/4HANA (Manage Bank Chains app)
Version(s) - S4CORE 107, 108, 109

Medium

4.3

3772838

[CVE-2026-76963] Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform

Product - SAP NetWeaver and ABAP Platform
Version(s) - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758

Medium

4.3

3736494

[CVE-2026-58234] Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)

Product - SAP Process Integration (SOAP Adapter)
Version(s) - MESSAGING 7.50, SAP_XIAF 7.50

Low

2.2

To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.