Critical Vulnerabilities in SAP Products
9 September 2026
Attackers can exploit multiple vulnerabilities in SAP Products to execute arbitrary commands, obtain sensitive credentials, replace or delete tenant data and perform unauthorised actions. Patch immediately.
Critical Vulnerabilities in SAP Products
Attackers can exploit multiple vulnerabilities in SAP Products to execute arbitrary commands, obtain sensitive credentials, replace or delete tenant data and perform unauthorised actions. Patch immediately.
Background
SAP has released security updates to address multiple vulnerabilities (CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768) affecting SAP Products.
The vulnerabilities have Common Vulnerability Scoring System (CVSS) scores of: CVE-2026-44756 at 10.0, CVE-2026-58240 at 9.8, CVE-2026-76969 at 9.4 and CVE-2026-66768 at 9.0 out of 10.
Impact
These vulnerabilities could allow attackers to execute arbitrary commands on a victim's machine through SAP GUI for Java, register unauthorised components with the SAP NetWeaver Message Server to perform unauthorised actions, obtain sensitive credentials and replace or delete tenant data in multi-tenant CAP applications, and cause abnormal program termination in the EPP processing library.
Successful exploitation could result in a high impact on the confidentiality, integrity and availability of affected systems.
Affected Products
These vulnerabilities affect the following products:
SAP Extended Passport (EPP) Processing versions:
KRNL64NUC 7.22 and 7.22EXT
KRNL64UC 7.22, 7.53 and 8.04
WEBDISP 9.16, 9.18, 9.19 and 9.20
KERNEL 7.22, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18,9.19, and 9.20
SAP NetWeaver (Message Server) versions:
KERNEL 9.16, 9.18, 9.19 and 9.20
SAP Cloud Application Programming Model (CAP): sap/cds-mtxs versions:
Version 1.18.3 and earlier
Version 2.7.6 and earlier
Version 3.9.6 and earlier
Version 4.0.2 and earlier
SAP NetWeaver (SAP GUI for Java) version:
BC-FES-JAV 8.10
Users and administrators should refer to the vendor advisory for the full list of affected versions.
Recommendations
Users and administrators of affected products are advised to update to the latest versions immediately.
References
https://me.sap.com/notes/3747649 (opens in new tab)
https://me.sap.com/notes/3759472 (opens in new tab)
https://me.sap.com/notes/3798315 (opens in new tab)
https://me.sap.com/notes/3781729 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-44756 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-58240 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-76969 (opens in new tab)
https://nvd.nist.gov/vuln/detail/CVE-2026-66768 (opens in new tab)
