Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.
September 2026 Notes
Monthly Summary and Highlights
This month the total number has been 20 notes (19 new and 1 update), 11 fewer than in August. This month 4 Hot News have been published, the same amount as in the previous period. As for high-criticality notes, there are 5, three fewer than in August. Medium and low notes will not be reviewed, so we will provide detail on a total of 9 notes (all those with a CVSS of 7 or higher).
We have a total of 20 notes for the whole month (19 new and 1 update to notes from previous months).
We will review in detail a total of 9 notes, all of high criticality and Hot News:
-
The highest-criticality note of the month (CVSS 10.0) is a Hot News and is related to “Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing”.
-
The second note in criticality (CVSS 9.8) is another Hot News and is related to “Missing Authentication check in SAP NetWeaver (Message Server)”.
-
The third note in criticality (CVSS 9.4) is another Hot News and is related to “Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)”.
-
The fourth note in criticality (CVSS 9.0) is the last Hot News of the month and is related to “Improper Access Control in SAP NetWeaver (SAP GUI for Java)”.
-
The fifth note we will review (CVSS 8.8) is of high criticality (update) and concerns “Privilege Escalation vulnerability in SAP ABAP Developer Tools”.
-
The sixth note we will review (CVSS 8.5) is of high criticality and concerns “XML External Entity (XXE) Vulnerability in SAP Integration Suite”.
-
The seventh note we will review (CVSS 7.8) is of high criticality and concerns “Insecure Deserialization in SAP NetWeaver Business Client”.
-
The eighth note we will review (CVSS 7.7) is of high criticality and concerns “Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform”.
-
The ninth and last note we will review (CVSS 7.4) is of high criticality and concerns “CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation)”.
This month the most predominant type has been “Cross-Site Request Forgery (CSRF)” (3/20 on patch day).
In the chart we can see the classification of September’s notes, as well as the evolution and classification of previous months (only Sec. Tuesday / Patch Day – by SAP notes):
Full details
The full details of the most relevant notes are as follows (in English):
-
Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing (3747649): A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 10,0/10 [CVE-2026-44756].
-
Missing Authentication check in SAP NetWeaver (Message Server) (3759472): SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. CVSS v3 Base Score 9,8/10 [CVE-2026-58240].
-
Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) (3798315): @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data. A temporary workaround is available. CVSS v3 Base Score 9,4/10 [CVE-2026-76969].
-
Improper Access Control in SAP NetWeaver (SAP GUI for Java) (3781729): SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim’s machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system. CVSS v3 Base Score 9,0/10 [CVE-2026-66768].
-
Privilege Escalation vulnerability in SAP ABAP Developer Tools (3772411): SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability. A temporary workaround is available. CVSS v3 Base Score 8,8/10 [CVE-2026-58243].
-
XML External Entity (XXE) Vulnerability in SAP Integration Suite (3792978): SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity. CVSS v3 Base Score 8,5/10 [CVE-2026-76958].
-
Insecure Deserialization in SAP NetWeaver Business Client (3784138): SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application. CVSS v3 Base Score 7,8/10 [CVE-2026-76967].
-
Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform (3757002): SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user’s session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application. CVSS v3 Base Score 7,7/10 [CVE-2026-66767].
-
CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) (3791068): An unauthenticated attacker could send a specially crafted HTTP/1.1 chunked request containing a CR-LF sequence inside a quoted chunk extension string, causing Jetty to misinterpret the request boundary and smuggle an additional HTTP request to the backend server. This vulnerability has a high impact on confidentiality and integrity with no impact on availability of the application. A temporary workaround is available. CVSS v3 Base Score 7,4/10 [CVE-2026-2332].
Reference links
References, in English, from SAP and Onapsis:
Affected resources
The full list of affected systems/components is as follows:
-
SAP Extended Passport (EPP) Processing: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20.
-
SAP NetWeaver (Message Server): KERNEL 9.16, 9.18, 9.19, 9.20.
-
sap/cds-mtxs: <=1.18.3, <=2.7.6, <=3.9.6, <=4.0.2.
-
SAP NetWeaver (SAP GUI for Java): BC-FES-JAV 8.10.
-
SAP ABAP Developer Tools: SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920.
-
SAP Integration Suite: Cloud Integration – Trading Partner Management V2 2.9.2, B2B Integration Factory – Cloud Integration – Trading Partner Management 1.10.0.
-
SAP NetWeaver Business Client: BC-WD-CLT-BUS 8.00, 8.10.
-
SAP NetWeaver Application Server for ABAP and ABAP Platform: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20.
-
SAP Commerce Cloud (Search And Navigation): COM_CLOUD 2211, 2211-JDK21.




