A CVSS 10 Passport Flaw Leads SAP’s September Security Fixes
The passport was meant to carry trust between SAP systems. A malformed one can now cross the boundary instead.
SAP’s September 2026 Security Patch Day contains 19 new security notes and one updated note. At the top is CVE-2026-44756, a CVSS 10 memory-corruption flaw in Extended Passport processing. An unauthenticated attacker can send a crafted network request with a malformed EPP header, trigger undefined behaviour and crash affected components. SAP’s vendor-authored record rates the potential impact to confidentiality, integrity and availability as high.
That perfect score is not the bulletin’s only urgent item. Three other vulnerabilities are rated critical. Two provide unauthenticated network paths into server-side trust boundaries, while the fourth can turn a manipulated SAP backend into command execution on a user’s machine.
Four critical fixes should lead the change window
CVE-2026-58240, rated 9.8, affects the SAP NetWeaver Message Server. The server does not properly verify the authenticity of internal application-server components during registration. An unauthenticated attacker with network access can register an unauthorised component and potentially perform unauthorised actions with high impact across all three security properties.
CVE-2026-76969, rated 9.4, sits in the SAP Cloud Application Programming Model package @sap/cds-mtxs. In multitenant applications with extensibility enabled, insufficient checks can let an unauthenticated attacker obtain credentials and replace or delete tenant data. The affected package lines extend through versions 1.18.3, 2.7.6, 3.9.6 and 4.0.2.
CVE-2026-66768, rated 9.0, affects SAP GUI for Java 8.10. A low-privileged attacker who can manipulate the connected backend can abuse a trust-level policy failure. If the victim interacts with the malicious content, arbitrary commands can run on the victim’s machine. This is not an unauthenticated server takeover, but it crosses from a backend session into the endpoint that an administrator or business user trusts.
These four issues deserve separate deployment checks. The affected component lists are different, and patching one does not mitigate the others. Internet exposure, partner connectivity, internal reachability and administrator workstation use should determine the order inside the critical tier.
The complete September bulletin
The table below evaluates every note in SAP’s public bulletin. SAP does not publish exact fixed-release numbers or general workarounds in the index. Where those details are absent, the required action is to retrieve and apply the corresponding SAP Security Note through an authorised support account. SAP and the vendor-authored CVE records do not state that any of these flaws are being actively exploited. No public proof of concept was identified during BlackTree’s review on 8 September.
| Note and score | Impact and prerequisites | Affected products and versions | Remediation and exposure status |
|---|---|---|---|
| 3747649 CVE-2026-44756 CVSS 10.0 | Memory corruption in Extended Passport processing. An unauthenticated network attacker sends a malformed EPP header, potentially causing high confidentiality, integrity and availability impact. | KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.53 and 8.04; WEBDISP 9.16, 9.18, 9.19 and 9.20; KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20. | Apply SAP Security Note 3747649. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3759472 CVE-2026-58240 CVSS 9.8 | Missing authentication in NetWeaver Message Server. An unauthenticated network attacker can register an unauthorised internal application-server component and potentially perform unauthorised actions. | KERNEL 9.16, 9.18, 9.19 and 9.20. | Apply SAP Security Note 3759472. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3798315 CVE-2026-76969 CVSS 9.4 | Credential disclosure in multitenant SAP CAP applications using @sap/cds-mtxs with extensibility enabled. Crafted unauthenticated requests can expose credentials and allow tenant data to be replaced or deleted. | Package versions through 1.18.3, 2.7.6, 3.9.6 and 4.0.2. | Apply SAP Security Note 3798315 and update the package line in use. A workaround is not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3781729 CVE-2026-66768 CVSS 9.0 | SAP GUI for Java does not enforce a trust-level policy. A low-privileged attacker must manipulate the connected backend, and victim interaction is required before arbitrary commands can run on the victim machine. | BC-FES-JAV 8.10. | Apply SAP Security Note 3781729. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3772411, updated CVE-2026-58243 CVSS 8.8 | Missing authorisation in ABAP Developer Tools. A low-privileged attacker can perform unauthorised database operations, read or modify data and disrupt access. | SAP_BASIS 750 through 758, 816, 918 and 920. | Apply the updated SAP Security Note 3772411. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3792978 CVE-2026-76958 CVSS 8.5 | XML external entity processing in SAP Integration Suite. A low-privileged attacker can submit crafted XML, read server files through monitoring or logging and potentially exhaust resources. Integrity is not affected. | Cloud Integration, Trading Partner Management V2 2.9.2; B2B Integration Factory, Trading Partner Management 1.10.0. | Apply SAP Security Note 3792978. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3784138 CVE-2026-76967 CVSS 7.8 | Insecure deserialisation in NetWeaver Business Client. A local low-privileged attacker can replace stored data that is processed at the next launch, leading to arbitrary code execution in the user’s context. | BC-WD-CLT-BUS 8.00 and 8.10. | Apply SAP Security Note 3784138. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3757002 CVE-2026-66767 CVSS 7.7 | Memory corruption in NetWeaver AS ABAP and ABAP Platform. An unauthenticated crafted packet can reprocess a buffered request and may hijack another user’s session under narrow timing conditions. | KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.53 and 8.04; KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20. | Apply SAP Security Note 3757002. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3791068 CVE-2026-2332 CVSS 7.4 in SAP bulletin | Eclipse Jetty HTTP/1.1 parsing can enable request smuggling through crafted chunk extensions and quoted strings containing line breaks. A network attacker needs no privileges, but exploitation complexity is high. | SAP COM_CLOUD 2211 and 2211-JDK21. Underlying Jetty ranges are 9.4.0 to 9.4.59, 10.0.0 to 10.0.27, 11.0.0 to 11.0.28, 12.0.0 to 12.0.32 and 12.1.0 to 12.1.6. | Apply SAP Security Note 3791068. Exact SAP fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3750721 CVE-2026-76968 CVSS 6.5 | Information disclosure in SAP Web Dispatcher, ICM and Content Server. A low-privileged authenticated attacker can reach certain administrative interfaces and obtain sensitive system-state data. | KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT and 7.53; WEBDISP 7.22_EXT, 7.53, 7.54, 7.77, 7.93 and 9.16; CONTSERV 7.53 and 7.54; KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19 and 9.20. | Apply SAP Security Note 3750721. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3756450 CVE-2026-44766 CVSS 6.5 | SQL injection in S/4HANA Intercompany Matching and Reconciliation. A low-privileged authenticated user can inject malicious input and read sensitive data. | SAPSCORE 136; S4CORE 104 through 109. | Apply SAP Security Note 3756450. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3786489 CVE-2026-76971 CVSS 6.5 | Server-side request forgery in SAP Manufacturing Integration and Intelligence. An authenticated attacker can cause outbound requests and combine the flaw with XML or XSL processing for script execution. Victim interaction is required. | XMII 15.4 and 15.5. | Apply SAP Security Note 3786489. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3787345 CVE-2026-34477 CVSS 5.9 in SAP bulletin | Apache Log4j can silently ignore the verifyHostName TLS setting in affected appenders. A network attacker able to present a certificate trusted by the configured or default trust store could perform interception. HTTP Appender is not affected. | SAP COM_CLOUD 2211 and 2211-JDK21. Underlying Log4j Core ranges are 2.12.0 to before 2.25.4 and 3.0.0-alpha1 to 3.0.0-beta3. | Apply SAP Security Note 3787345. Exact SAP fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3783189 CVE-2026-76977 CVSS 4.3 | Clickjacking through SAPUI5 Frame Options Allowlist. An unauthenticated attacker hosts a malicious page and needs an authenticated victim to interact with it, potentially causing unintended actions. | SAP_UI 750 and 754 through 758, plus 816; UI_700 200. | Apply SAP Security Note 3783189. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3365276 CVE-2026-76960 CVSS 4.3 in SAP bulletin | Cross-site request forgery in S/4HANA Finance Advanced Payment Management. A low-privileged attacker crafts a link or page and requires an authenticated victim to interact with it. | S4CORE 105, 106 and 107. | Apply SAP Security Note 3365276. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3371336 CVE-2026-76961 CVSS 4.3 in SAP bulletin | Cross-site request forgery in S/4HANA Finance Advanced Payment Management. A low-privileged attacker crafts a link or page and requires an authenticated victim to interact with it. | S4CORE 108. | Apply SAP Security Note 3371336. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3365311 CVE-2026-76959 CVSS 4.3 in SAP bulletin | Cross-site request forgery in S/4HANA Finance Advanced Payment Management. A low-privileged attacker crafts a link or page and requires an authenticated victim to interact with it. | UIAPFI70 800, 900, 901 and 902. | Apply SAP Security Note 3365311. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3657599 CVE-2026-76962 CVSS 4.3 | Missing authorisation in S/4HANA Manage Bank Chains. A low-privileged authenticated attacker can delete entries outside the intended access boundary, causing low availability impact. | S4CORE 107, 108 and 109. | Apply SAP Security Note 3657599. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3772838 CVE-2026-76963 CVSS 4.3 | Missing authorisation in NetWeaver and ABAP Platform. An authenticated attacker can access sensitive security settings and system configuration. | SAP_BASIS 700, 701, 702, 731, 740 and 750 through 758. | Apply SAP Security Note 3772838. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
| 3736494 CVE-2026-58234 CVSS 2.2 | Denial of service in the SAP Process Integration SOAP Adapter. A privileged user can send deeply nested entities, temporarily increasing processor load and degrading responsiveness. | MESSAGING 7.50; SAP_XIAF 7.50. | Apply SAP Security Note 3736494. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified. |
What defenders should do now
- Inventory the affected kernel, Web Dispatcher, NetWeaver, CAP, GUI, S/4HANA and integration components before choosing a single maintenance window.
- Prioritise externally reachable and partner-reachable EPP, Message Server and multitenant CAP deployments.
- Treat SAP GUI for Java as an endpoint-security issue as well as an SAP patching issue. A manipulated backend can put the user workstation at risk.
- Retrieve each relevant Security Note from SAP for exact package instructions, dependencies and any implementation details that are not present in the public index.
- After patching, review registrations to Message Server, unusual EPP parsing failures, tenant-management requests, suspicious SAP GUI child processes and unexpected outbound requests from SAP MII.
Security teams should not let the CVSS 10 headline hide the shape of this release. The most consequential theme is trust: a passport accepted at a network boundary, a server component allowed to register, a tenant request allowed to reach credentials and a backend allowed to influence a desktop client. Patching closes the disclosed flaws, but exposure review shows which of those trust paths an attacker could reach before the change window begins.
Sources
- SAP Security Patch Day, September 2026, published 8 September 2026. SAP provided no publication time.
- MITRE CVE record for the Extended Passport issue, published 8 September 2026 at 00:10:16 UTC.
- MITRE CVE record for the NetWeaver Message Server issue, published 8 September 2026 at 00:10:55 UTC and updated at 10:34:59 UTC.
- MITRE CVE record for the SAP CAP multitenancy issue, published 8 September 2026 at 00:12:55 UTC and updated at 10:34:58 UTC.
- MITRE CVE record for the SAP GUI for Java issue, published 8 September 2026 at 00:11:15 UTC and updated at 10:34:59 UTC.
- MITRE CVE record for the updated ABAP Developer Tools issue, originally published 11 August 2026 at 00:16:07 UTC.


