Inprosec a través de sus servicios, como el SAP Security Assessment, ayuda a sus clientes a mejorar los niveles de seguridad de sus sistemas SAP.
Notas septiembre 2026
Resumen y highlights del Mes
Este mes el número total ha sido de 20 notas (19 nuevas y 1 actualización), 11 menos que en agosto. Este mes se han publicado 4 Hot News, la misma cantidad que en el periodo anterior. En cuanto a notas de criticidad alta, hay 5, tres menos con respecto a agosto. Las notas medias y bajas no serán revisadas, por lo que daremos detalle de un total de 9 notas (todas las que tengan un CVSS de 7 o mayor).
Tenemos un total de 20 notas para todo el mes (19 nuevas y 1 actualización de notas de meses anteriores).
Revisaremos en detalle un total de 9 notas, todas de criticidad alta y Hot News:
-
La nota más alta en criticidad del mes (CVSS 10,0) es una Hot News y está relacionada con “Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing”.
-
La segunda nota en criticidad (CVSS 9,8) es otra Hot News y está relacionada con “Missing Authentication check in SAP NetWeaver (Message Server)”.
-
La tercera nota en criticidad (CVSS 9,4) es otra Hot News y está relacionada con “Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)”.
-
La cuarta nota en criticidad (CVSS 9,0) es la última Hot News del mes y está relacionada con “Improper Access Control in SAP NetWeaver (SAP GUI for Java)”.
-
La quinta nota que revisaremos (CVSS 8,8) es de criticidad alta (actualización) y trata sobre “Privilege Escalation vulnerability in SAP ABAP Developer Tools”.
-
La sexta nota que revisaremos (CVSS 8,5) es de criticidad alta y trata sobre “XML External Entity (XXE) Vulnerability in SAP Integration Suite”.
-
La séptima nota que revisaremos (CVSS 7,8) es de criticidad alta y trata sobre “Insecure Deserialization in SAP NetWeaver Business Client”.
-
La octava nota que revisaremos (CVSS 7,7) es de criticidad alta y trata sobre “Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform”.
-
La novena y última nota que revisaremos (CVSS 7,4) es de criticidad alta y trata sobre “CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation)”.
Este mes el tipo más predominante ha sido “Cross-Site Request Forgery (CSRF)” (3/20 en el patch day).
En la gráfica podemos ver la clasificación de las notas de septiembre, además de la evolución y clasificación de los últimos meses anteriores (solo las notas del Sec. Tuesday / Patch Day – by SAP):
Detalle completo
El detalle completo de las notas más relevantes es el siguiente (en inglés):
-
Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing (3747649): A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application. A temporary workaround is available. CVSS v3 Base Score 10,0/10 [CVE-2026-44756].
-
Missing Authentication check in SAP NetWeaver (Message Server) (3759472): SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. CVSS v3 Base Score 9,8/10 [CVE-2026-58240].
-
Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) (3798315): @sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data. A temporary workaround is available. CVSS v3 Base Score 9,4/10 [CVE-2026-76969].
-
Improper Access Control in SAP NetWeaver (SAP GUI for Java) (3781729): SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim’s machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system. CVSS v3 Base Score 9,0/10 [CVE-2026-66768].
-
Privilege Escalation vulnerability in SAP ABAP Developer Tools (3772411): SAP ABAP Development Tools does not perform necessary authorization checks for certain functionality, allowing an attacker with low privileges to execute unauthorized database operations against SAP NetWeaver AS ABAP. Successful exploitation could allow the attacker to read sensitive data, modify application data, and disrupt access for legitimate users, resulting in high impact on confidentiality, integrity, and availability. A temporary workaround is available. CVSS v3 Base Score 8,8/10 [CVE-2026-58243].
-
XML External Entity (XXE) Vulnerability in SAP Integration Suite (3792978): SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read sensitive file contents from the server and expose them through monitoring or logging output, resulting in a high impact on confidentiality. It could also lead to resource exhaustion, causing a low impact on availability. There is no impact on integrity. CVSS v3 Base Score 8,5/10 [CVE-2026-76958].
-
Insecure Deserialization in SAP NetWeaver Business Client (3784138): SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is processed and could lead to arbitrary code execution in the context of the user. This results in a high impact on confidentiality, integrity and availability of the application. CVSS v3 Base Score 7,8/10 [CVE-2026-76967].
-
Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform (3757002): SAP NetWeaver Application Server for ABAP and ABAP Platform allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user’s session under narrow timing conditions. Successful exploitation could result in high impact on confidentiality and integrity, with low impact on availability of the application. CVSS v3 Base Score 7,7/10 [CVE-2026-66767].
-
CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) (3791068): An unauthenticated attacker could send a specially crafted HTTP/1.1 chunked request containing a CR-LF sequence inside a quoted chunk extension string, causing Jetty to misinterpret the request boundary and smuggle an additional HTTP request to the backend server. This vulnerability has a high impact on confidentiality and integrity with no impact on availability of the application. A temporary workaround is available. CVSS v3 Base Score 7,4/10 [CVE-2026-2332].
Enlaces de referencia
Referencias, en inglés de SAP y Onapsis:
Recursos afectados
El listado completo de los sistemas/componentes afectados es el siguiente:
-
SAP Extended Passport (EPP) Processing: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20.
-
SAP NetWeaver (Message Server): KERNEL 9.16, 9.18, 9.19, 9.20.
-
sap/cds-mtxs: <=1.18.3, <=2.7.6, <=3.9.6, <=4.0.2.
-
SAP NetWeaver (SAP GUI for Java): BC-FES-JAV 8.10.
-
SAP ABAP Developer Tools: SAP_BASIS 750, 751, 752, 753, 754, 755, 756, 757, 758, 816, 918, 920.
-
SAP Integration Suite: Cloud Integration – Trading Partner Management V2 2.9.2, B2B Integration Factory – Cloud Integration – Trading Partner Management 1.10.0.
-
SAP NetWeaver Business Client: BC-WD-CLT-BUS 8.00, 8.10.
-
SAP NetWeaver Application Server for ABAP and ABAP Platform: KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20.
-
SAP Commerce Cloud (Search And Navigation): COM_CLOUD 2211, 2211-JDK21.




