BlackTree Security · Infrastructure · Automation · AI

A CVSS 10 Passport Flaw Leads SAP’s September Security Fixes

The passport was meant to carry trust between SAP systems. A malformed one can now cross the boundary instead.

SAP’s September 2026 Security Patch Day contains 19 new security notes and one updated note. At the top is CVE-2026-44756, a CVSS 10 memory-corruption flaw in Extended Passport processing. An unauthenticated attacker can send a crafted network request with a malformed EPP header, trigger undefined behaviour and crash affected components. SAP’s vendor-authored record rates the potential impact to confidentiality, integrity and availability as high.

That perfect score is not the bulletin’s only urgent item. Three other vulnerabilities are rated critical. Two provide unauthenticated network paths into server-side trust boundaries, while the fourth can turn a manipulated SAP backend into command execution on a user’s machine.

Four critical fixes should lead the change window

CVE-2026-58240, rated 9.8, affects the SAP NetWeaver Message Server. The server does not properly verify the authenticity of internal application-server components during registration. An unauthenticated attacker with network access can register an unauthorised component and potentially perform unauthorised actions with high impact across all three security properties.

CVE-2026-76969, rated 9.4, sits in the SAP Cloud Application Programming Model package @sap/cds-mtxs. In multitenant applications with extensibility enabled, insufficient checks can let an unauthenticated attacker obtain credentials and replace or delete tenant data. The affected package lines extend through versions 1.18.3, 2.7.6, 3.9.6 and 4.0.2.

CVE-2026-66768, rated 9.0, affects SAP GUI for Java 8.10. A low-privileged attacker who can manipulate the connected backend can abuse a trust-level policy failure. If the victim interacts with the malicious content, arbitrary commands can run on the victim’s machine. This is not an unauthenticated server takeover, but it crosses from a backend session into the endpoint that an administrator or business user trusts.

These four issues deserve separate deployment checks. The affected component lists are different, and patching one does not mitigate the others. Internet exposure, partner connectivity, internal reachability and administrator workstation use should determine the order inside the critical tier.

The complete September bulletin

The table below evaluates every note in SAP’s public bulletin. SAP does not publish exact fixed-release numbers or general workarounds in the index. Where those details are absent, the required action is to retrieve and apply the corresponding SAP Security Note through an authorised support account. SAP and the vendor-authored CVE records do not state that any of these flaws are being actively exploited. No public proof of concept was identified during BlackTree’s review on 8 September.

Note and scoreImpact and prerequisitesAffected products and versionsRemediation and exposure status
3747649
CVE-2026-44756
CVSS 10.0
Memory corruption in Extended Passport processing. An unauthenticated network attacker sends a malformed EPP header, potentially causing high confidentiality, integrity and availability impact.KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.53 and 8.04; WEBDISP 9.16, 9.18, 9.19 and 9.20; KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20.Apply SAP Security Note 3747649. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3759472
CVE-2026-58240
CVSS 9.8
Missing authentication in NetWeaver Message Server. An unauthenticated network attacker can register an unauthorised internal application-server component and potentially perform unauthorised actions.KERNEL 9.16, 9.18, 9.19 and 9.20.Apply SAP Security Note 3759472. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3798315
CVE-2026-76969
CVSS 9.4
Credential disclosure in multitenant SAP CAP applications using @sap/cds-mtxs with extensibility enabled. Crafted unauthenticated requests can expose credentials and allow tenant data to be replaced or deleted.Package versions through 1.18.3, 2.7.6, 3.9.6 and 4.0.2.Apply SAP Security Note 3798315 and update the package line in use. A workaround is not stated publicly. Active exploitation is not stated. No public PoC was identified.
3781729
CVE-2026-66768
CVSS 9.0
SAP GUI for Java does not enforce a trust-level policy. A low-privileged attacker must manipulate the connected backend, and victim interaction is required before arbitrary commands can run on the victim machine.BC-FES-JAV 8.10.Apply SAP Security Note 3781729. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3772411, updated
CVE-2026-58243
CVSS 8.8
Missing authorisation in ABAP Developer Tools. A low-privileged attacker can perform unauthorised database operations, read or modify data and disrupt access.SAP_BASIS 750 through 758, 816, 918 and 920.Apply the updated SAP Security Note 3772411. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3792978
CVE-2026-76958
CVSS 8.5
XML external entity processing in SAP Integration Suite. A low-privileged attacker can submit crafted XML, read server files through monitoring or logging and potentially exhaust resources. Integrity is not affected.Cloud Integration, Trading Partner Management V2 2.9.2; B2B Integration Factory, Trading Partner Management 1.10.0.Apply SAP Security Note 3792978. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3784138
CVE-2026-76967
CVSS 7.8
Insecure deserialisation in NetWeaver Business Client. A local low-privileged attacker can replace stored data that is processed at the next launch, leading to arbitrary code execution in the user’s context.BC-WD-CLT-BUS 8.00 and 8.10.Apply SAP Security Note 3784138. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3757002
CVE-2026-66767
CVSS 7.7
Memory corruption in NetWeaver AS ABAP and ABAP Platform. An unauthenticated crafted packet can reprocess a buffered request and may hijack another user’s session under narrow timing conditions.KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.53 and 8.04; KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20.Apply SAP Security Note 3757002. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3791068
CVE-2026-2332
CVSS 7.4 in SAP bulletin
Eclipse Jetty HTTP/1.1 parsing can enable request smuggling through crafted chunk extensions and quoted strings containing line breaks. A network attacker needs no privileges, but exploitation complexity is high.SAP COM_CLOUD 2211 and 2211-JDK21. Underlying Jetty ranges are 9.4.0 to 9.4.59, 10.0.0 to 10.0.27, 11.0.0 to 11.0.28, 12.0.0 to 12.0.32 and 12.1.0 to 12.1.6.Apply SAP Security Note 3791068. Exact SAP fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3750721
CVE-2026-76968
CVSS 6.5
Information disclosure in SAP Web Dispatcher, ICM and Content Server. A low-privileged authenticated attacker can reach certain administrative interfaces and obtain sensitive system-state data.KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT and 7.53; WEBDISP 7.22_EXT, 7.53, 7.54, 7.77, 7.93 and 9.16; CONTSERV 7.53 and 7.54; KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 9.16, 9.18, 9.19 and 9.20.Apply SAP Security Note 3750721. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3756450
CVE-2026-44766
CVSS 6.5
SQL injection in S/4HANA Intercompany Matching and Reconciliation. A low-privileged authenticated user can inject malicious input and read sensitive data.SAPSCORE 136; S4CORE 104 through 109.Apply SAP Security Note 3756450. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3786489
CVE-2026-76971
CVSS 6.5
Server-side request forgery in SAP Manufacturing Integration and Intelligence. An authenticated attacker can cause outbound requests and combine the flaw with XML or XSL processing for script execution. Victim interaction is required.XMII 15.4 and 15.5.Apply SAP Security Note 3786489. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3787345
CVE-2026-34477
CVSS 5.9 in SAP bulletin
Apache Log4j can silently ignore the verifyHostName TLS setting in affected appenders. A network attacker able to present a certificate trusted by the configured or default trust store could perform interception. HTTP Appender is not affected.SAP COM_CLOUD 2211 and 2211-JDK21. Underlying Log4j Core ranges are 2.12.0 to before 2.25.4 and 3.0.0-alpha1 to 3.0.0-beta3.Apply SAP Security Note 3787345. Exact SAP fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3783189
CVE-2026-76977
CVSS 4.3
Clickjacking through SAPUI5 Frame Options Allowlist. An unauthenticated attacker hosts a malicious page and needs an authenticated victim to interact with it, potentially causing unintended actions.SAP_UI 750 and 754 through 758, plus 816; UI_700 200.Apply SAP Security Note 3783189. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3365276
CVE-2026-76960
CVSS 4.3 in SAP bulletin
Cross-site request forgery in S/4HANA Finance Advanced Payment Management. A low-privileged attacker crafts a link or page and requires an authenticated victim to interact with it.S4CORE 105, 106 and 107.Apply SAP Security Note 3365276. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3371336
CVE-2026-76961
CVSS 4.3 in SAP bulletin
Cross-site request forgery in S/4HANA Finance Advanced Payment Management. A low-privileged attacker crafts a link or page and requires an authenticated victim to interact with it.S4CORE 108.Apply SAP Security Note 3371336. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3365311
CVE-2026-76959
CVSS 4.3 in SAP bulletin
Cross-site request forgery in S/4HANA Finance Advanced Payment Management. A low-privileged attacker crafts a link or page and requires an authenticated victim to interact with it.UIAPFI70 800, 900, 901 and 902.Apply SAP Security Note 3365311. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3657599
CVE-2026-76962
CVSS 4.3
Missing authorisation in S/4HANA Manage Bank Chains. A low-privileged authenticated attacker can delete entries outside the intended access boundary, causing low availability impact.S4CORE 107, 108 and 109.Apply SAP Security Note 3657599. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3772838
CVE-2026-76963
CVSS 4.3
Missing authorisation in NetWeaver and ABAP Platform. An authenticated attacker can access sensitive security settings and system configuration.SAP_BASIS 700, 701, 702, 731, 740 and 750 through 758.Apply SAP Security Note 3772838. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.
3736494
CVE-2026-58234
CVSS 2.2
Denial of service in the SAP Process Integration SOAP Adapter. A privileged user can send deeply nested entities, temporarily increasing processor load and degrading responsiveness.MESSAGING 7.50; SAP_XIAF 7.50.Apply SAP Security Note 3736494. Exact fixed releases and a workaround are not stated publicly. Active exploitation is not stated. No public PoC was identified.

What defenders should do now

  • Inventory the affected kernel, Web Dispatcher, NetWeaver, CAP, GUI, S/4HANA and integration components before choosing a single maintenance window.
  • Prioritise externally reachable and partner-reachable EPP, Message Server and multitenant CAP deployments.
  • Treat SAP GUI for Java as an endpoint-security issue as well as an SAP patching issue. A manipulated backend can put the user workstation at risk.
  • Retrieve each relevant Security Note from SAP for exact package instructions, dependencies and any implementation details that are not present in the public index.
  • After patching, review registrations to Message Server, unusual EPP parsing failures, tenant-management requests, suspicious SAP GUI child processes and unexpected outbound requests from SAP MII.

Security teams should not let the CVSS 10 headline hide the shape of this release. The most consequential theme is trust: a passport accepted at a network boundary, a server component allowed to register, a tenant request allowed to reach credentials and a backend allowed to influence a desktop client. Patching closes the disclosed flaws, but exposure review shows which of those trust paths an attacker could reach before the change window begins.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *