SAP Security Patch Day – September 2026
Chapters
Share Article
Let's Talk SAP Security
Have questions about SAP Security? We’re here to help. Contact Us
SAP security should remain a key priority, and this month’s Patch Day once again demonstrates why. With 19 newly released Security Notes in September, the volume remains substantial and continues to highlight the risks associated with delaying security updates. Many successful attacks still exploit vulnerabilities for which patches are already available. Applying security patches as quickly as possible remains one of the most effective ways to reduce exposure to known vulnerabilities and limit the attack surface across SAP landscapes.
This month’s SAP Security Patch Day includes 19 new Security Notes released today, together with 1 updated Security Note and 1 note released between Patch Days. Each should be carefully assessed and prioritized based on its relevance and potential impact. Below, we highlight the most important Security Notes from September and explain what they could mean for your SAP landscape.
SAP environments are becoming increasingly complex, often combining on-premise systems, cloud services, and hybrid architectures. This makes patch management much more than a standard maintenance task. With many interconnected components and dependencies, patching can be difficult to plan, resource-intensive, and time-consuming, increasing the risk that important fixes are overlooked. At SecurityBridge, we recognize these challenges.
The SecurityBridge Patch Management for SAP solution helps organizations identify missing patches across their SAP landscape, providing clear visibility, impact analysis, and automated implementation support. By offering a system-wide overview, it helps accelerate patching cycles and strengthen continuous threat monitoring, contributing to a more secure and resilient SAP environment throughout 2026.
SAP Security Notes September 2026
Highlights
Patches required for on-premise systems, client devices and cloud services. A clear example of the dynamic attack surface of a modern SAP landscape!
Summary by Severity
The September release contains a total of 21 patches for the following severities:
| Severity | Number | Hot News | 5 |
|---|---|
High | 5 |
Medium | 10 |
Low | 1 |
| Note | Description | Severity | CVSS |
|---|---|---|---|
| 3771065 | [CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter) Priority: HotNews Released on: 8/11/26 Components: CEC-SCC-PLA-PL Category: Program error | Hot News | 10.0 |
| 3747649 | [CVE-2026-44756] Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing Priority: HotNews Released on: 9/8/26 Components: BC-CST-DP Category: Program error | Hot News | 10.0 |
| 3759472 | [ CVE-2026-58240] Missing Authentication check in SAP NetWeaver (Message Server) Priority: HotNews Released on: 9/8/26 Components: BC-CST-MS Category: Program error | Hot News | 9.8 |
| 3798315 | [CVE-2026-76969] Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) Priority: HotNews Released on: 9/8/26 Components: BC-XS-CDX-SEC Category: Program error | Hot News | 9.4 |
| 3781729 | [CVE-2026-66768] Improper Access Control in SAP NetWeaver (SAP GUI for Java) Priority: HotNews Released on: 9/8/26 Components: BC-FES-JAV Category: Program error | Hot News | 9.0 |
| 3772411 | [CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools Priority: Correction with high priority Released on: 8/11/26 Components: BC-DWB-AIE-DP Category: Program error | High | 8.8 |
| 3792978 | [CVE-2026-76958] XML External Entity (XXE) Vulnerability in SAP Integration Suite Priority: Correction with high priority Released on: 9/8/26 Components: LOD-HCI-PI-TPM Category: Program error | High | 8.5 |
| 3784138 | [CVE-2026-76967] Insecure Deserialization in SAP NetWeaver Business Client Priority: Correction with high priority Released on: 9/8/26 Components: BC-FES-BUS Category: Program error | High | 7.8 |
| 3757002 | [CVE-2026-66767] Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform Priority: Correction with high priority Released on: 9/8/26 Components: BC-MID-RFC Category: Program error | High | 7.7 |
| 3791068 | [CVE-2026-2332] CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) Priority: Correction with high priority Released on: 9/8/26 Components: CEC-SCC-COM-SRC-SER Category: Program error | High | 7.4 |
| 3750721 | [CVE-2026-76968] Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server Priority: Correction with medium priority Released on: 9/8/26 Components: BC-CST-IC Category: Program error | Medium | 6.5 |
| 3756450 | [CVE-2026-44766] – SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation) Priority: Correction with medium priority Released on: 9/8/26 Components: FIN-CS-ICR Category: Program error | Medium | 6.5 |
| 3786489 | [CVE-2026-76971] Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence Priority: Correction with medium priority Released on: 9/8/26 Components: MFG-MII-CON Category: Consulting | Medium | 6.5 |
| 3787345 | [CVE-2026-34477] Security Misconfiguration vulnerability due to use of Apache Log4j in SAP Commerce Cloud (Search and Navigation) Priority: Correction with medium priority Released on: 9/8/26 Components: CEC-SCC-COM-SRC-SER Category: Program error | Medium | 5.9 |
| 3783189 | [CVE-2026-76977] Clickjacking vulnerability in SAPUI5(Frame Options Allowlist) Priority: Correction with medium priority Released on: 9/8/26 Components: CA-UI5-COR Category: Program error | Medium | 4.3 |
| 3657599 | [CVE-2026-76962] Missing Authorization check in SAP S/4HANA (Manage Bank Chains app) Priority: Correction with medium priority Released on: 9/8/26 Components: FI-BL-MD Category: Program error | Medium | 4.3 |
| 3365311 | [CVE-2026-76959] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) Priority: Correction with medium priority Released on: 9/8/26 Components: FIN-FSCM-PF Category: Program error | Medium | 4.3 |
| 3365276 | [CVE-2026-76960] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) Priority: Correction with medium priority Released on: 9/8/26 Components: FIN-FSCM-PF Category: Program error | Medium | 4.3 |
| 3371336 | [CVE-2026-76961] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) Priority: Correction with medium priority Released on: 9/8/26 Components: FIN-FSCM-PF Category: Program error | Medium | 4.3 |
| 3772838 | [CVE-2026-76963] Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform Priority: Correction with medium priority Released on: 9/8/26 Components: BC-I18 Category: Program error | Medium | 4.3 |
| 3736494 | [CVE-2026-58234] Denial of Service vulnerability in SAP Process Integration(SOAP Adapter) Priority: Correction with low priority Released on: 9/8/26 Components: BC-XI-CON-SOP Category: Program error | Low | 2.2 |
SAP Security Notes August 2026
Highlights
A relatively large number of notes overall, with SAP Manufacturing Integration and Intelligence in the spotlight.
Summary by Severity
The August release contains a total of 29 patches (including in-between patches) for the following severities:
| Severity | Number | Hot News | 4 |
|---|---|
High | 9 |
Medium | 14 |
Low | 2 |
| Note | Description | Severity | CVSS |
|---|---|---|---|
| 3747367 | [CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP Priority: HotNews Released on: 7/14/26 Components: BC-FES-ITS Category: Program error | Hot News | 9.9 |
| 3765948 | [CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence Priority: HotNews Released on: 8/11/26 Components: MFG-MII Category: Program error | Hot News | 9.9 |
| 3714806 | [CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform Priority: HotNews Released on: 8/11/26 Components: BC-ABA-SC Category: Program error | Hot News | 9.8 |
| 3758900 | [CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence Priority: HotNews Released on: 8/11/26 Components: MFG-MII Category: Program error | Hot News | 9.1 |
| 3772411 | [CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools Priority: Correction with high priority Released on: 8/11/26 Components: BC-DWB-AIE-DP Category: Program error | High | 8.8 |
| 3732471 | [CVE-2026-34259] OS Command Injection Vulnerability in SAP Forecasting & Replenishment Priority: Correction with high priority Released on: 5/12/26 Components: SCM-FRE-FRP Category: Program error | High | 8.2 |
| 3773203 | [CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX Priority: Correction with high priority Released on: 8/11/26 Components: CEC-SCC-CLA-ENV-EMG Category: Program error | High | 8.1 |
| 3756565 | [CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server) Priority: Correction with high priority Released on: 8/11/26 Components: BI-BIP-SRV Category: Program error | High | 7.9 |
| 3759854 | [CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence Priority: Correction with high priority Released on: 8/11/26 Components: MFG-MII Category: Program error | High | 7.6 |
| 3773304 | [CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach) Priority: Correction with high priority Released on: 7/14/26 Components: BC-CTS-TMS-PLS Category: Program error | High | 7.6 |
| 3758657 | [CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Priority: Correction with high priority Released on: 8/11/26 Components: MFG-MII Category: Program error | High | 7.3 |
| 3758910 | [CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence Priority: Correction with high priority Released on: 8/11/26 Components: MFG-MII Category: Program error | High | 7.3 |
| 3786038 | [CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter) Priority: Correction with high priority Released on: 8/11/26 Components: BC-XS-APR Category: Program error | High | 7.0 |
| 3753141 | [CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence Priority: Correction with medium priority Released on: 8/11/26 Components: BI-RA-WBI Category: Program error | Medium | 6.5 |
| 3766473 | [CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence Priority: Correction with medium priority Released on: 8/11/26 Components: CA-EPT-SMI Category: Program error | Medium | 6.3 |
| 3721424 | [CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP Priority: Correction with medium priority Released on: 8/11/26 Components: BC-WD-UR Category: Program error | Medium | 6.3 |
| 3758318 | [CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services) Priority: Correction with medium priority Released on: 8/11/26 Components: BC-SRV-FP Category: Program error | Medium | 6.3 |
| 3772071 | [CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5 Priority: Correction with medium priority Released on: 8/11/26 Components: CA-UI5-COR Category: Program error | Medium | 6.1 |
| 3745182 | [CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CST-DP Category: Program error | Medium | 5.5 |
| 3540688 | [CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework Priority: Correction with medium priority Released on: 7/22/25 Components: FI-LOC-CA-XX Category: Program error | Medium | 5.5 |
| 3756674 | [CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CST-DP Category: Program error | Medium | 5.3 |
| 3725940 | [CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CCM-PRN Category: Program error | Medium | 5.3 |
| 3770649 | [CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools) Priority: Correction with medium priority Released on: 8/11/26 Components: BI-BIP-INV Category: Program error | Medium | 4.3 |
| 3781137 | [CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII) Priority: Correction with medium priority Released on: 8/11/26 Components: MFG-MII Category: Program error | Medium | 4.3 |
| 3413033 | [CVE-2026-58246 ] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform Priority: Correction with medium priority Released on: 7/28/26 Components: BC-MID-ICF Category: Program error | Medium | 4.3 |
| 3669608 | [CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items) Priority: Correction with medium priority Released on: 11/19/25 Components: FI-FIO-AR-PAY Category: Program error | Medium | 4.3 |
| 3752864 | [CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard) Priority: Correction with medium priority Released on: 8/11/26 Components: BC-CTS-TMS-CTR Category: Program error | Medium | 4.2 |
| 3763028 | [CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning) Priority: Correction with low priority Released on: 8/11/26 Components: SCM-APO-PPS-MMP Category: Program error | Low | 3.8 |
| 3739913 | [CVE-2026-44762 ] Security Misconfiguration in SAP Data Services Management Console Priority: Correction with low priority Released on: 8/11/26 Components: EIM-DS-DEP Category: Program error | Low | 3.7 |
