Decoding the world of cybersecurity

SAP fixes critical enterprise software flaws

SAP’s September security release includes a CVSS 10.0 memory-corruption flaw and three other critical vulnerabilities across NetWeaver, cloud application components, and SAP GUI for Java.

SAP fixes critical enterprise software flaws
Summary
  • SAP released 19 new security notes and one update on 8 September.
  • CVE-2026-44756 carries a CVSS score of 10.0 across multiple SAP kernel and Web Dispatcher versions.
  • Other critical issues affect NetWeaver authentication, multitenant cloud credentials, and SAP GUI for Java access controls.

SAP has issued fixes for four critical vulnerabilities across core enterprise infrastructure, including a maximum-severity memory-corruption flaw affecting multiple kernel and Web Dispatcher versions.

SAP published 19 new security notes and one update to an existing note on 8 September as part of its monthly Security Patch Day.

The most severe issue, CVE-2026-44756, carries a CVSS score of 10.0 and affects Extended Passport processing across a wide range of SAP kernel and Web Dispatcher versions. SAP describes the weakness as a memory-corruption vulnerability.

CVE-2026-58240 affects the SAP NetWeaver Message Server, is rated 9.8, and concerns a missing authentication check. CVE-2026-76969, rated 9.4, can disclose credentials in multitenant applications using SAP’s Cloud Application Programming Model.

A fourth critical issue, CVE-2026-66768, is an improper-access-control vulnerability in SAP GUI for Java with a CVSS score of 9.0.

The range of affected components makes the release broader than a single application patch. SAP infrastructure commonly connects finance, procurement, human resources, manufacturing, supplier management, analytics, identity, and other processes that carry direct operational dependencies.

A vulnerability in a message server, kernel component, Web Dispatcher, development framework, or client application can therefore sit inside a larger trust path even where the affected component is not directly exposed to the public internet.

SAP strongly recommends that customers review and apply the relevant security fixes. In large estates, that requires more than identifying the highest CVSS score. Organisations have to determine which versions are actually deployed, what each component can reach, which business processes depend on it, and how quickly changes can move through testing and production.

Enterprise SAP systems often contain significant customisation and integrations with third-party software. Maintenance windows can be narrow, particularly around finance, manufacturing, supply chain, or reporting processes. A critical fix can consequently create an operational trade-off between rapid remediation and the risk of destabilising a system whose downtime affects the wider business.

The September release also spans traditional and cloud-oriented SAP architecture. The credential-disclosure issue in multitenant applications built with SAP’s Cloud Application Programming Model shows that the security surface is no longer confined to established on-premises servers.

Development frameworks and shared application services can propagate security assumptions into multiple applications at once. Where a vulnerable library or framework is embedded across several services, asset discovery needs to identify the applications that inherit the exposure rather than stopping at the package name.

SAP has not stated that the four leading critical vulnerabilities are being exploited in attacks. Their urgency is therefore based on technical severity, affected architecture, and the consequences that successful exploitation could create, rather than confirmed hostile use.

That distinction affects prioritisation. Confirmed exploitation normally pushes remediation towards the front of the queue, while an unexploited critical flaw still requires rapid treatment where the affected system is exposed, privileged, or central to business operations.

The September release ultimately tests the quality of SAP asset management as much as patch deployment. Organisations that know which components, versions, and integrations they operate can establish an order of work. Those relying on an incomplete inventory risk discovering the vulnerable system only after a security note has become an incident.

×