{"id":14644,"date":"2026-09-11T09:03:03","date_gmt":"2026-09-11T07:03:03","guid":{"rendered":"https:\/\/www.inprosec.com\/?p=14644"},"modified":"2026-09-11T09:03:03","modified_gmt":"2026-09-11T07:03:03","slug":"sap-security-notes-september-2026","status":"publish","type":"post","link":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/","title":{"rendered":"SAP Security Notes, September 2026"},"content":{"rendered":"<p><b>Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems.<\/b><\/p>\n\n<h2>September 2026 Notes<\/h2>\n<h3>Monthly Summary and Highlights<\/h3>\n<div>\n<div class=\"elementToProof\">This month the total number has been <b>20 notes<\/b> (19 new and 1 update), 11 fewer than in August. This month <b>4 Hot News<\/b> have been published, the same amount as in the previous period. As for high-criticality notes, there are <b>5<\/b>, three fewer than in August. Medium and low notes will not be reviewed, so we will provide detail on a total of <b>9 notes<\/b> (all those with a CVSS of 7 or higher).<\/div>\n<div><\/div>\n<div class=\"elementToProof\">We have a total of <b>20 notes<\/b> for the whole month (19 new and 1 update to notes from previous months).<\/div>\n<div><\/div>\n<div class=\"elementToProof\">We will review in detail a total of 9 notes, all of high criticality and Hot News:<\/div>\n<div><\/div>\n<ol start=\"1\" data-path-to-node=\"7\">\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The highest-criticality note of the month (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>10.0<\/b><\/span>) is a Hot News and is related to <b>&#8220;Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The second note in criticality (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9.8<\/b><\/span>) is another Hot News and is related to <b>&#8220;Missing Authentication check in SAP NetWeaver (Message Server)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The third note in criticality (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9.4<\/b><\/span>) is another Hot News and is related to <b>&#8220;Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The fourth note in criticality (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9.0<\/b><\/span>) is the last Hot News of the month and is related to <b>&#8220;Improper Access Control in SAP NetWeaver (SAP GUI for Java)&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The fifth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8.8<\/b><\/span>) is of high criticality (update) and concerns <b>&#8220;Privilege Escalation vulnerability in SAP ABAP Developer Tools&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The sixth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8.5<\/b><\/span>) is of high criticality and concerns <b>&#8220;XML External Entity (XXE) Vulnerability in SAP Integration Suite&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The seventh note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.8<\/b><\/span>) is of high criticality and concerns <b>&#8220;Insecure Deserialization in SAP NetWeaver Business Client&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The eighth note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.7<\/b><\/span>) is of high criticality and concerns <b>&#8220;Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform&#8221;<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\">The ninth and last note we will review (<b>CVSS <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7.4<\/b><\/span>) is of high criticality and concerns <b>&#8220;CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation)&#8221;<\/b>.<\/div>\n<\/li>\n<\/ol>\n<div class=\"elementToProof\">This month the most predominant type has been <b>&#8220;Cross-Site Request Forgery (CSRF)&#8221;<\/b> (3\/20 on patch day).<\/div>\n<div><\/div>\n<div class=\"elementToProof\">In the chart we can see the classification of September&#8217;s notes, as well as the evolution and classification of previous months (only Sec. Tuesday \/ Patch Day \u2013 by SAP notes):<\/div>\n<div class=\"elementToProof\">\n<div><\/div>\n<\/div>\n<\/div>\n<p><img decoding=\"async\" class=\"aligncenter  wp-image-14646\" src=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg\" alt=\"\" width=\"704\" height=\"370\" srcset=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg 1200w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026-300x158.jpg 300w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026-1024x538.jpg 1024w, https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026-600x315.jpg 600w\" sizes=\"(max-width: 704px) 100vw, 704px\" \/><\/p>\n<h2>Full details<\/h2>\n<p class=\"elementToProof\">The <b>full details of the most relevant notes<\/b> are as follows (in English):<\/p>\n<ul>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing (<\/b><a id=\"OWA513b7fbe-6de5-e045-8ab9-0712c0673d2d\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3747649\"><b><u>3747649<\/u><\/b><\/a><b>)<\/b>: A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>10,0<\/b><\/span><b>\/10 [<\/b><a id=\"OWAd04d98b0-a060-9d3d-83d0-88d53bf835bf\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44756\"><b><u>CVE-2026-44756<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Missing Authentication check in SAP NetWeaver (Message Server) (<\/b><a id=\"OWA7949492b-709d-647b-974f-f357fc8eef05\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3759472\"><b><u>3759472<\/u><\/b><\/a><b>)<\/b>: SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9,8<\/b><\/span><b>\/10 [<\/b><a id=\"OWA911c3c74-fa6c-2037-6064-219524e40a8b\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58240\"><b><u>CVE-2026-58240<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) (<\/b><a id=\"OWA700e1da9-4771-c6fb-2b21-7fd7d202b07e\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3798315\"><b><u>3798315<\/u><\/b><\/a><b>)<\/b>: @sap\/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9,4<\/b><\/span><b>\/10 [<\/b><a id=\"OWAb9304e9d-6e66-4140-9951-bb2fe3a1c5ed\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-76969\"><b><u>CVE-2026-76969<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Improper Access Control in SAP NetWeaver (SAP GUI for Java) (<\/b><a id=\"OWA9df2e252-bb21-9f94-48cb-e84abb05ed8b\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3781729\"><b><u>3781729<\/u><\/b><\/a><b>)<\/b>: SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim&#8217;s machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ff0000;\"><b>9,0<\/b><\/span><b>\/10 [<\/b><a id=\"OWA65603fd1-7aca-3777-9678-1afe6b08fc2f\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66768\"><b><u>CVE-2026-66768<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Privilege Escalation vulnerability in SAP ABAP Developer Tools (<\/b><a id=\"OWAc6de8009-d41c-bd55-a3ed-9c410f5229a1\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3772411\"><b><u>3772411<\/u><\/b><\/a><b>)<\/b>: SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8,8<\/b><\/span><b>\/10 [<\/b><a id=\"OWA732f368c-ec6f-3117-7979-532737c724e2\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-58243\"><b><u>CVE-2026-58243<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>XML External Entity (XXE) Vulnerability in SAP Integration Suite (<\/b><a id=\"OWAfdf93109-e153-8a3e-c650-1b457ab5310c\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3792978\"><b><u>3792978<\/u><\/b><\/a><b>)<\/b>: SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>8,5<\/b><\/span><b>\/10 [<\/b><a id=\"OWA4add1180-d16d-bb4d-b7ac-7a5205426b14\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-76958\"><b><u>CVE-2026-76958<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Insecure Deserialization in SAP NetWeaver Business Client (<\/b><a id=\"OWAaeffd274-69de-264c-1707-cc8ba87e393d\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3784138\"><b><u>3784138<\/u><\/b><\/a><b>)<\/b>: SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,8<\/b><\/span><b>\/10 [<\/b><a id=\"OWA9cde2d87-789b-3c90-a4aa-784ed231090e\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-76967\"><b><u>CVE-2026-76967<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform (<\/b><a id=\"OWA0bd0759f-52ca-80af-99c2-0f28a03dc6be\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3757002\"><b><u>3757002<\/u><\/b><\/a><b>)<\/b>: SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user&#8217;s session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,7<\/b><\/span><b>\/10 [<\/b><a id=\"OWAc87a6736-3489-b779-ef89-d7ac852483bc\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-66767\"><b><u>CVE-2026-66767<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) (<\/b><a id=\"OWA395d77d1-83d3-5ffa-daab-25e5a47b1026\" class=\"OWAAutoLink\" href=\"https:\/\/me.sap.com\/notes\/3791068\"><b><u>3791068<\/u><\/b><\/a><b>)<\/b>: An unauthenticated attacker could send a specially crafted HTTP\/1.1 chunked request containing a CR-LF sequence inside a quoted chunk extension string, causing Jetty to misinterpret the request boundary and smuggle an additional HTTP request to the backend server. This vulnerability has a high impact on confidentiality and integrity with no impact on availability of the application. A temporary workaround is available. <b>CVSS v3 Base Score <\/b><span class=\"spanWithBackgroundColor\" style=\"color: #ffcc00;\"><b>7,4<\/b><\/span><b>\/10 [<\/b><a id=\"OWA78e4c8d1-90f9-972e-38ee-2064801a6ec7\" class=\"OWAAutoLink\" href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2332\"><b><u>CVE-2026-2332<\/u><\/b><\/a><b>]<\/b>.<\/div>\n<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\">Reference links<\/strong><\/p>\n<div class=\"elementToProof\">\n<p>References, in English, from SAP and Onapsis:<\/p>\n<ul>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><a id=\"OWA6e15bdbc-6bc9-883e-8981-30e10a09deba\" class=\"OWAAutoLink\" title=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/september-2026.html?isu_page=1\" href=\"https:\/\/support.sap.com\/en\/my-support\/knowledge-base\/security-notes-news\/september-2026.html?isu_page=1\">SAP Security Patch Day &#8211; September 2026<\/a><\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><a id=\"OWA92f72bdd-1436-cda2-db92-4cb5386ca866\" class=\"OWAAutoLink\" title=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-september-2026\/?_gl=1*1x86tct*_up*MQ..*_ga*MTg2NzY3NzIzNy4xNzg5MDQ4Mjg1*_ga_2HEPRR6DH5*czE3ODkwNDgyODUkbzEkZzEkdDE3ODkwNDgyOTMkajUyJGwwJGgyMTM4MzUyNzk4\" href=\"https:\/\/onapsis.com\/blog\/sap-security-patch-day-september-2026\/?_gl=1*1x86tct*_up*MQ..*_ga*MTg2NzY3NzIzNy4xNzg5MDQ4Mjg1*_ga_2HEPRR6DH5*czE3ODkwNDgyODUkbzEkZzEkdDE3ODkwNDgyOTMkajUyJGwwJGgyMTM4MzUyNzk4\">SAP Security Notes: September 2026 Patch Day &#8211; Onapsis<\/a><\/div>\n<\/li>\n<\/ul>\n<\/div>\n<h2><strong style=\"color: #014888; font-family: inherit; font-size: 1.6rem; letter-spacing: 0em;\">Affected resources<\/strong><\/h2>\n<div>The full list of affected systems\/components is as follows:<\/div>\n<div><\/div>\n<ul>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Extended Passport (EPP) Processing:<\/b> KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver (Message Server):<\/b> KERNEL 9.16, 9.18, 9.19, 9.20.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>sap\/cds-mtxs:<\/b> &lt;=1.18.3, &lt;=2.7.6, &lt;=3.9.6, &lt;=4.0.2.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver (SAP GUI for Java):<\/b> BC-FES-JAV 8.10.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP ABAP Developer Tools:<\/b> SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Integration Suite:<\/b> Cloud Integration &#8211; Trading Partner Management V2 2.9.2, B2B Integration Factory &#8211; Cloud Integration &#8211; Trading Partner Management 1.10.0.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver Business Client:<\/b> BC-WD-CLT-BUS 8.00, 8.10.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP NetWeaver Application Server for ABAP and ABAP Platform:<\/b> KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20.<\/div>\n<\/li>\n<li>\n<div class=\"elementToProof\" role=\"presentation\"><b>SAP Commerce Cloud (Search And Navigation):<\/b> COM_CLOUD 2211, 2211-JDK21.<\/div>\n<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>Through services such as the SAP Security Assessment, Inprosec helps its clients improve the security levels of their SAP systems. September 2026 Notes Monthly Summary and Highlights This month the total number has been 20 notes (19 new and 1 update), 11 fewer than in August. This month 4 Hot News have been published, the&#8230;<\/p>\n","protected":false},"author":6,"featured_media":14646,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[95,61],"tags":[150],"class_list":["post-14644","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sap-notes","category-sap-security-en-2","tag-sap-notes"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v26.3 (Yoast SEO v28.4) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>SAP Security Notes, September 2026 - Inprosec<\/title>\n<meta name=\"description\" content=\"All updates to SAP systems notes from september 2026, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"SAP Security Notes, September 2026\" \/>\n<meta property=\"og:description\" content=\"All updates to SAP systems notes from september 2026, to stay current and improve the security levels of your SAP systems.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/\" \/>\n<meta property=\"og:site_name\" content=\"Inprosec\" \/>\n<meta property=\"article:published_time\" content=\"2026-09-11T07:03:03+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"630\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Fernando Mosquera\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Fernando Mosquera\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"7 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/\"},\"author\":{\"name\":\"Fernando Mosquera\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"headline\":\"SAP Security Notes, September 2026\",\"datePublished\":\"2026-09-11T07:03:03+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/\"},\"wordCount\":1271,\"commentCount\":0,\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Notas-SAP-septiembre-2026.jpg\",\"keywords\":[\"SAP Notes\"],\"articleSection\":[\"SAP Notes\",\"SAP Security\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/\",\"name\":\"SAP Security Notes, September 2026 - Inprosec\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Notas-SAP-septiembre-2026.jpg\",\"datePublished\":\"2026-09-11T07:03:03+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\"},\"description\":\"All updates to SAP systems notes from september 2026, to stay current and improve the security levels of your SAP systems.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Notas-SAP-septiembre-2026.jpg\",\"contentUrl\":\"https:\\\/\\\/www.inprosec.com\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/Notas-SAP-septiembre-2026.jpg\",\"width\":1200,\"height\":630},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/sap-security-notes-september-2026\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"SAP Security Notes, September 2026\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#website\",\"url\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/\",\"name\":\"Inprosec\",\"description\":\"Information security is our priority.\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.inprosec.com\\\/en\\\/#\\\/schema\\\/person\\\/b05a40c0c3e81b819075dd95a10532e2\",\"name\":\"Fernando Mosquera\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g\",\"caption\":\"Fernando Mosquera\"}}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"SAP Security Notes, September 2026 - Inprosec","description":"All updates to SAP systems notes from september 2026, to stay current and improve the security levels of your SAP systems.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/","og_locale":"en_US","og_type":"article","og_title":"SAP Security Notes, September 2026","og_description":"All updates to SAP systems notes from september 2026, to stay current and improve the security levels of your SAP systems.","og_url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/","og_site_name":"Inprosec","article_published_time":"2026-09-11T07:03:03+00:00","og_image":[{"width":1200,"height":630,"url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg","type":"image\/jpeg"}],"author":"Fernando Mosquera","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Fernando Mosquera","Est. reading time":"7 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#article","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/"},"author":{"name":"Fernando Mosquera","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"headline":"SAP Security Notes, September 2026","datePublished":"2026-09-11T07:03:03+00:00","mainEntityOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/"},"wordCount":1271,"commentCount":0,"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg","keywords":["SAP Notes"],"articleSection":["SAP Notes","SAP Security"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/","url":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/","name":"SAP Security Notes, September 2026 - Inprosec","isPartOf":{"@id":"https:\/\/www.inprosec.com\/en\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#primaryimage"},"image":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#primaryimage"},"thumbnailUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg","datePublished":"2026-09-11T07:03:03+00:00","author":{"@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2"},"description":"All updates to SAP systems notes from september 2026, to stay current and improve the security levels of your SAP systems.","breadcrumb":{"@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#primaryimage","url":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg","contentUrl":"https:\/\/www.inprosec.com\/wp-content\/uploads\/2026\/09\/Notas-SAP-septiembre-2026.jpg","width":1200,"height":630},{"@type":"BreadcrumbList","@id":"https:\/\/www.inprosec.com\/en\/sap-security-notes-september-2026\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.inprosec.com\/en\/"},{"@type":"ListItem","position":2,"name":"SAP Security Notes, September 2026"}]},{"@type":"WebSite","@id":"https:\/\/www.inprosec.com\/en\/#website","url":"https:\/\/www.inprosec.com\/en\/","name":"Inprosec","description":"Information security is our priority.","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.inprosec.com\/en\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.inprosec.com\/en\/#\/schema\/person\/b05a40c0c3e81b819075dd95a10532e2","name":"Fernando Mosquera","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/199e6c54b14f5b5ddf7e11a9bb0b455c3bed7a9a1a738b7be5c2572878e69d1a?s=96&d=mm&r=g","caption":"Fernando Mosquera"}}]}},"_links":{"self":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14644","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/comments?post=14644"}],"version-history":[{"count":1,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14644\/revisions"}],"predecessor-version":[{"id":14648,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/posts\/14644\/revisions\/14648"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media\/14646"}],"wp:attachment":[{"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/media?parent=14644"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/categories?post=14644"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.inprosec.com\/en\/wp-json\/wp\/v2\/tags?post=14644"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}