September 2026 security updates
Non-Product Related Assistance Request for existing cases, user IDs, Portal support and more
Request for existing cases, user IDs, Portal support and more
SAP Security Patch Day - September 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.
On 8 th of September 2026, SAP security patch day saw the release of 19 new security notes. There is 1 update to previously released security note.
[ CVE-2026-44756 ] Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
Product - SAP Extended Passport (EPP) Processing Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
[ CVE-2026-58240 ] Missing Authentication check in SAP NetWeaver (Message Server)
Product - SAP NetWeaver (Message Server) Version(s) - KERNEL 9.16, 9.18, 9.19, 9.20
[ CVE-2026-76969 ] Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
Library - sap/cds-mtxs Version(s) <=1.18.3, <=2.7.6, <=3.9.6, <=4.0.2
[ CVE-2026-66768 ] Improper Access Control in SAP NetWeaver (SAP GUI for Java)
Product - SAP NetWeaver (SAP GUI for Java) Version(s) - BC-FES-JAV 8.10
Update to Security Note released on August 2026 Patch Day:
[ CVE-2026-58243 ] Privilege Escalation vulnerability in SAP ABAP Developer Tools
Product - SAP ABAP Developer Tools Version(s) - SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 816, SAP_BASIS 918, SAP_BASIS 920
[ CVE-2026-76958 ] XML External Entity (XXE) Vulnerability in SAP Integration Suite
Product - SAP Integration Suite Version(s): Cloud Integration - Trading Partner Management V2 2.9.2, B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0
[ CVE-2026-76967 ] Insecure Deserialization in SAP NetWeaver Business Client
Product - SAP NetWeaver Business Client Version(s) - BC-WD-CLT-BUS 8.00, 8.10
[ CVE-2026-66767 ] Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Product - SAP NetWeaver Application Server for ABAP and ABAP Platform Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
[ CVE-2026-2332 ] CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud ( And )
Product - SAP Commerce Cloud ( And ) Version(s) - COM_CLOUD 2211, 2211-JDK21
[ CVE-2026-76968 ] Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Product - SAP Web Dispatcher, Internet Communication Manager and SAP Content Server Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, WEBDISP 7.22_EXT, 7.53, 7.54, 7.77, 7.93, 9.16, CONTSERV 7.53, 7.54, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19, 9.20
[ CVE-2026-44766 ] SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)
Product - SAP S/4HANA (Intercompany Matching and Reconciliation) Version(s) - SAPSCORE 136, S4CORE 104, 105, 106, 107, 108, 109
[ CVE-2026-76971 ] Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence
Product - SAP Manufacturing Integration and Intelligence Version(s) - XMII 15.4, 15.5
[ CVE-2026-34477 ] Security Misconfiguration vulnerability due to use of Apache Log4j in SAP Commerce Cloud ( and )
Product - SAP Commerce Cloud ( and ) Version(s) - COM_CLOUD 2211, 2211-JDK21
[ CVE-2026-76977 ] Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)
Product - SAPUI5(Frame Options Allowlist) Version(s) - SAP_UI 750, 754, 755, 756, 757, 758, 816, UI_700 200
[ CVE-2026-76960 ] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Product - SAP S/4HANA (Finance for Advanced Payment Management) Version(s) - S4CORE 105, 106, 107
[ CVE-2026-76961 ] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Product - SAP S/4HANA (Finance for Advanced Payment Management) Version(s) - S4CORE 108
[ CVE-2026-76959 ] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Product - SAP S/4HANA (Finance for Advanced Payment Management) Version(s) - UIAPFI70 800, 900, 901, 902
[ CVE-2026-76962 ] Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)
Product - SAP S/4HANA (Manage Bank Chains app) Version(s) - S4CORE 107, 108, 109
[ CVE-2026-76963 ] Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform
Product - SAP NetWeaver and ABAP Platform Version(s) - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758
[ CVE-2026-58234 ] Denial of Service vulnerability in SAP Process Integration (SOAP Adapter)
Product - SAP Process Integration (SOAP Adapter) Version(s) - MESSAGING 7.50, SAP_XIAF 7.50
To know more the security researchers and research companies who have contributed for security patches of this month, visit here . SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio. Archived blogs from years are available here . If you have any or feedback this post, you can write to [email protected] .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
