SAP Security Notes, September 2026

Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.

September 2026 Notes

Monthly Summary and Highlights

This month the total number has been 20 notes (19 new and 1 update), 11 fewer than in August. This month 4 Hot News have been published, the same amount as in the previous period. As for high-criticality notes, there are 5, three fewer than in August. Medium and low notes will not be reviewed, so we will provide detail on a total of 9 notes (all those with a CVSS of 7 or higher).
We have a total of 20 notes for the whole month (19 new and 1 update to notes from previous months).
We will review in detail a total of 9 notes, all of high criticality and Hot News:
This month the most predominant type has been “Cross-Site Request Forgery (CSRF)” (3/20 on patch day).
In the chart we can see the classification of September’s notes, as well as the evolution and classification of previous months (only Sec. Tuesday / Patch Day – by SAP notes):

Full details

The full details of the most relevant notes are as follows (in English):

 

Reference links

Affected resources

The full list of affected systems/components is as follows:

Did you like it?

Share it on social media!

Leave a Reply

Your email address will not be published. Required fields are marked *

Fill out this field
Fill out this field
Please enter a valid email address.
You need to agree with the terms to proceed

Categories

Calendar of posts

Our services

keyboard_arrow_up