ON 8 September 2026 SAP released 19 security notes and one update as part of its monthly Patch Day, addressing several high‑severity flaws across Extended Passport Processing, NetWeaver, and Cloud Application Programming. The advisory flags five CVEs in total, four rated Critical and one High, with the most severe being CVE-2026-44756 (CVSSv3 10.0) in the Extended Passport Protocol library.
The report notes that there is no confirmed active exploitation at the time of publication, but unpatched, internet‑facing systems remain at immediate risk.
The article outlines how the vulnerabilities can be exploited and which product components are affected. CVE-2026-44756 involves a memory safety issue in EPP processing that can be triggered by unauthenticated network requests, potentially causing memory corruption. CVE-2026-58240 concerns the NetWeaver Message Server, where internal component authenticity during registration may be bypassed, allowing an attacker to register a malicious component.
CVE-2026-76969 exposes multitenant Cloud Application Programming instances to credential theft via crafted requests. Additional affected versions are listed for Extended Passport (KRNL64NUC 7.22, KRNL64UC 7.22–8.04, WEBDISP 9.16–9.20, KERNEL 7.22–9.20), NetWeaver Message Server in KERNEL 9.16–9.20, and sap/cds-mtxs libraries across several versions (1.18.3, 2.7.6, 3.9.6, 4.0.2).
SAP advises applying all updates from the SAP Security Advisory immediately, across development, testing, and production environments, and to review network logs for suspicious registration attempts targeting the Message Server.