Skip to content

SAP Security Patch Day – September 2026

Gert Jan
Gert-Jan Koster
SAP Security specialist
September 8, 2026
8 min read

Chapters

Share Article

Let's Talk SAP Security

Have questions about SAP Security? We’re here to help. Contact Us

Text Base Post Tile

SAP security should remain a key priority, and this month’s Patch Day once again demonstrates why. With 19 newly released Security Notes in September, the volume remains substantial and continues to highlight the risks associated with delaying security updates. Many successful attacks still exploit vulnerabilities for which patches are already available. Applying security patches as quickly as possible remains one of the most effective ways to reduce exposure to known vulnerabilities and limit the attack surface across SAP landscapes.

This month’s SAP Security Patch Day includes 19 new Security Notes released today, together with 1 updated Security Note and 1 note released between Patch Days. Each should be carefully assessed and prioritized based on its relevance and potential impact. Below, we highlight the most important Security Notes from September and explain what they could mean for your SAP landscape.

SAP environments are becoming increasingly complex, often combining on-premise systems, cloud services, and hybrid architectures. This makes patch management much more than a standard maintenance task. With many interconnected components and dependencies, patching can be difficult to plan, resource-intensive, and time-consuming, increasing the risk that important fixes are overlooked. At SecurityBridge, we recognize these challenges.

The SecurityBridge Patch Management for SAP solution helps organizations identify missing patches across their SAP landscape, providing clear visibility, impact analysis, and automated implementation support. By offering a system-wide overview, it helps accelerate patching cycles and strengthen continuous threat monitoring, contributing to a more secure and resilient SAP environment throughout 2026.

 

SAP Security Notes September 2026

Highlights

Patches required for on-premise systems, client devices and cloud services. A clear example of the dynamic attack surface of a modern SAP landscape!

Summary by Severity

The September release contains a total of 21 patches for the following severities:

SeverityNumber
Hot News
5
High
5
Medium
10
Low
1
NoteDescriptionSeverityCVSS
3771065[CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
Priority: HotNews
Released on: 8/11/26
Components: CEC-SCC-PLA-PL
Category: Program error
Hot News10.0
3747649[CVE-2026-44756] Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
Priority: HotNews
Released on: 9/8/26
Components: BC-CST-DP
Category: Program error
Hot News10.0
3759472[ CVE-2026-58240] Missing Authentication check in SAP NetWeaver (Message Server)
Priority: HotNews
Released on: 9/8/26
Components: BC-CST-MS
Category: Program error
Hot News9.8
3798315[CVE-2026-76969] Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
Priority: HotNews
Released on: 9/8/26
Components: BC-XS-CDX-SEC
Category: Program error
Hot News9.4
3781729[CVE-2026-66768] Improper Access Control in SAP NetWeaver (SAP GUI for Java)
Priority: HotNews
Released on: 9/8/26
Components: BC-FES-JAV
Category: Program error
Hot News9.0
3772411[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools
Priority: Correction with high priority
Released on: 8/11/26
Components: BC-DWB-AIE-DP
Category: Program error
High8.8
3792978[CVE-2026-76958] XML External Entity (XXE) Vulnerability in SAP Integration Suite
Priority: Correction with high priority
Released on: 9/8/26
Components: LOD-HCI-PI-TPM
Category: Program error
High8.5
3784138[CVE-2026-76967] Insecure Deserialization in SAP NetWeaver Business Client
Priority: Correction with high priority
Released on: 9/8/26
Components: BC-FES-BUS
Category: Program error
High7.8
3757002[CVE-2026-66767] Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Priority: Correction with high priority
Released on: 9/8/26
Components: BC-MID-RFC
Category: Program error
High7.7
3791068[CVE-2026-2332] CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation)
Priority: Correction with high priority
Released on: 9/8/26
Components: CEC-SCC-COM-SRC-SER
Category: Program error
High7.4
3750721[CVE-2026-76968] Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
Priority: Correction with medium priority
Released on: 9/8/26
Components: BC-CST-IC
Category: Program error
Medium6.5
3756450[CVE-2026-44766] – SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)
Priority: Correction with medium priority
Released on: 9/8/26
Components: FIN-CS-ICR
Category: Program error
Medium6.5
3786489[CVE-2026-76971] Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence
Priority: Correction with medium priority
Released on: 9/8/26
Components: MFG-MII-CON
Category: Consulting
Medium6.5
3787345[CVE-2026-34477] Security Misconfiguration vulnerability due to use of Apache Log4j in SAP Commerce Cloud (Search and Navigation)
Priority: Correction with medium priority
Released on: 9/8/26
Components: CEC-SCC-COM-SRC-SER
Category: Program error
Medium5.9
3783189[CVE-2026-76977] Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)
Priority: Correction with medium priority
Released on: 9/8/26
Components: CA-UI5-COR
Category: Program error
Medium4.3
3657599[CVE-2026-76962] Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)
Priority: Correction with medium priority
Released on: 9/8/26
Components: FI-BL-MD
Category: Program error
Medium4.3
3365311[CVE-2026-76959] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Priority: Correction with medium priority
Released on: 9/8/26
Components: FIN-FSCM-PF
Category: Program error
Medium4.3
3365276[CVE-2026-76960] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Priority: Correction with medium priority
Released on: 9/8/26
Components: FIN-FSCM-PF
Category: Program error
Medium4.3
3371336[CVE-2026-76961] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
Priority: Correction with medium priority
Released on: 9/8/26
Components: FIN-FSCM-PF
Category: Program error
Medium4.3
3772838[CVE-2026-76963] Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform
Priority: Correction with medium priority
Released on: 9/8/26
Components: BC-I18
Category: Program error
Medium4.3
3736494[CVE-2026-58234] Denial of Service vulnerability in SAP Process Integration(SOAP Adapter)
Priority: Correction with low priority
Released on: 9/8/26
Components: BC-XI-CON-SOP
Category: Program error
Low2.2

SAP Security Notes August 2026

Highlights

A relatively large number of notes overall, with SAP Manufacturing Integration and Intelligence in the spotlight.

Summary by Severity

The August release contains a total of 29 patches (including in-between patches) for the following severities:

   
       
                   

               

         
     
 
SeverityNumber
Hot News
4
High
9
Medium
14
Low
2
       
   
NoteDescriptionSeverityCVSS
3747367[CVE-2026-44747] Memory Corruption vulnerability in SAP NetWeaver Application Server ABAP
Priority: HotNews
Released on: 7/14/26
Components: BC-FES-ITS
Category: Program error
Hot News9.9
3765948[CVE-2026-44772] Code Injection vulnerability in SAP Manufacturing Integration and Intelligence
Priority: HotNews
Released on: 8/11/26
Components: MFG-MII
Category: Program error
Hot News9.9
3714806[CVE-2026-34265] Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Priority: HotNews
Released on: 8/11/26
Components: BC-ABA-SC
Category: Program error
Hot News9.8
3758900[CVE-2026-44758] Code Injection vulnerability in Manufacturing Integration and Intelligence
Priority: HotNews
Released on: 8/11/26
Components: MFG-MII
Category: Program error
Hot News9.1
3772411[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools
Priority: Correction with high priority
Released on: 8/11/26
Components: BC-DWB-AIE-DP
Category: Program error
High8.8
3732471[CVE-2026-34259] OS Command Injection Vulnerability in SAP Forecasting & Replenishment
Priority: Correction with high priority
Released on: 5/12/26
Components: SCM-FRE-FRP
Category: Program error
High8.2
3773203[CVE-2026-42945] Potential buffer overflow vulnerability affects SAP Commerce Cloud in public‑cloud deployments with NGINX
Priority: Correction with high priority
Released on: 8/11/26
Components: CEC-SCC-CLA-ENV-EMG
Category: Program error
High8.1
3756565[CVE-2026-66763] Credentials disclosure in SAP BusinessObjects Business Intelligence Platform (Central Management Server)
Priority: Correction with high priority
Released on: 8/11/26
Components: BI-BIP-SRV
Category: Program error
High7.9
3759854[CVE-2026-44763] Directory Traversal vulnerability in SAP Manufacturing Integration and Intelligence
Priority: Correction with high priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
High7.6
3773304[CVE-2026-58233] Remote Code Execution vulnerability in Enhanced Change and Transport System (CTS+) Attach Tool (ctsattach)
Priority: Correction with high priority
Released on: 7/14/26
Components: BC-CTS-TMS-PLS
Category: Program error
High7.6
3758657[CVE-2026-44765] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Priority: Correction with high priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
High7.3
3758910[CVE-2026-44764] Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Priority: Correction with high priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
High7.3
3786038[CVE-2026-58230] Multiple vulnerabilities in SAP Business AI Platform (Approuter)
Priority: Correction with high priority
Released on: 8/11/26
Components: BC-XS-APR
Category: Program error
High7.0
3753141[CVE-2026-58248] XML External Entity Injection in SAP BusinessObjects Business Intelligence
Priority: Correction with medium priority
Released on: 8/11/26
Components: BI-RA-WBI
Category: Program error
Medium6.5
3766473[CVE-2026-66770] SQL Injection vulnerability in SAP Social Intelligence
Priority: Correction with medium priority
Released on: 8/11/26
Components: CA-EPT-SMI
Category: Program error
Medium6.3
3721424[CVE-2026-66779] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-WD-UR
Category: Program error
Medium6.3
3758318[CVE-2026-58235] Use of Vulnerable Third-Party Component in SAP NetWeaver AS Java (Adobe Document Services)
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-SRV-FP
Category: Program error
Medium6.3
3772071[CVE-2026-66771] Cross Site Scripting (XSS) vulnerability in SAPUI5
Priority: Correction with medium priority
Released on: 8/11/26
Components: CA-UI5-COR
Category: Program error
Medium6.1
3745182[CVE-2026-58236] OS Command Injection vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CST-DP
Category: Program error
Medium5.5
3540688[CVE-2025-42947] Code Injection vulnerability in SAP FICA ODN framework
Priority: Correction with medium priority
Released on: 7/22/25
Components: FI-LOC-CA-XX
Category: Program error
Medium5.5
3756674[CVE-2026-58247] Memory Corruption vulnerability in SAP ABAP Platform
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CST-DP
Category: Program error
Medium5.3
3725940[CVE-2026-40130] Memory Corruption vulnerability in SAPSPrint Service
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CCM-PRN
Category: Program error
Medium5.3
3770649[CVE-2026-66772] Missing Authorization Check in SAP BusinessObjects Business Intelligence Platform (Admin Tools)
Priority: Correction with medium priority
Released on: 8/11/26
Components: BI-BIP-INV
Category: Program error
Medium4.3
3781137[CVE-2026-58244] Missing Authorization Check in SAP Manufacturing Integration and Intelligence (MII)
Priority: Correction with medium priority
Released on: 8/11/26
Components: MFG-MII
Category: Program error
Medium4.3
3413033[CVE-2026-58246 ] Information Disclosure vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
Priority: Correction with medium priority
Released on: 7/28/26
Components: BC-MID-ICF
Category: Program error
Medium4.3
3669608[CVE-2026-66764] Missing Authorization check in SAP S/4 HANA (Reprocess Bank Statement Items)
Priority: Correction with medium priority
Released on: 11/19/25
Components: FI-FIO-AR-PAY
Category: Program error
Medium4.3
3752864[CVE-2026-58241] Missing Authorization Check in SAP NetWeaver and ABAP Platform (Change and Transport System - Customer Transport Integration Wizard)
Priority: Correction with medium priority
Released on: 8/11/26
Components: BC-CTS-TMS-CTR
Category: Program error
Medium4.2
3763028[CVE-2026-58245] Hard-coded Credentials in SAP Advanced Planning and Optimization (Model Mix Planning)
Priority: Correction with low priority
Released on: 8/11/26
Components: SCM-APO-PPS-MMP
Category: Program error
Low3.8
3739913[CVE-2026-44762 ] Security Misconfiguration in SAP Data Services Management Console
Priority: Correction with low priority
Released on: 8/11/26
Components: EIM-DS-DEP
Category: Program error
Low3.7