September 2026 SAP Security Patch Day addresses five notable vulnerabilities across SAP Extended Passport Processing, SAP NetWeaver, and SAP Cloud Application Programming. The release includes four Critical and one High-severity vulnerabilities, with CVSS scores ranging from 8.8 to 10.0. No active exploitation or public proof-of-concept code has been confirmed for these vulnerabilities.
CVE-2026-44756 (CVSS 10.0): A critical memory corruption vulnerability in the SAP Extended Passport Protocol library allows an unauthenticated remote attacker to send a specially crafted protocol header. Successful exploitation can trigger memory corruption, potentially resulting in undefined behavior or application termination.[/subscribe_to_unlock_form]
September 2026 SAP Security Patch Day addresses five notable vulnerabilities across SAP Extended Passport Processing, SAP NetWeaver, and SAP Cloud Application Programming. The release includes four Critical and one High-severity vulnerabilities, with CVSS scores ranging from 8.8 to 10.0. No active exploitation or public proof-of-concept code has been confirmed for these vulnerabilities.
CVE-2026-44756 (CVSS 10.0): A critical memory corruption vulnerability in the SAP Extended Passport Protocol library allows an unauthenticated remote attacker to send a specially crafted protocol header. Successful exploitation can trigger memory corruption, potentially resulting in undefined behavior or application termination.[emaillocker id="1283"]
CVE-2026-58240 (CVSS 9.8): A critical authentication vulnerability in SAP NetWeaver Message Server allows a remote attacker to register an unauthorized component because the server does not properly validate the authenticity of internal components during registration. This can enable unauthorized access to the affected application environment.
CVE-2026-76969 (CVSS 9.4): A critical credential-disclosure vulnerability in multitenant SAP Cloud Application Programming environments allows attackers to obtain sensitive credentials through specially crafted requests, potentially compromising connected services or applications.
CVE-2026-66768 (CVSS 9.0): A critical vulnerability involving reliance on untrusted inputs in a security decision (CWE-807) can allow unauthorized behavior in affected SAP components when security decisions are made using insufficiently trusted input.
CVE-2026-58243 (CVSS 8.8): A high-severity missing authorization vulnerability (CWE-862) in SAP allows unauthorized users to access functionality without the required security permissions, potentially leading to unauthorized operations within the affected system.
We recommend you to update SAP to version 9.16, 1.18.3, 2.7.6, 3.9.6, or 4.0.2.
The following reports contain further technical details:
[/emaillocker]