Posting Date: 2026/09/21
【Vulnerability Alert】SAP Issues Major Security Advisory for Multiple Products Under Its Brand
- Subject:【Vulnerability Alert】SAP Issues Major Security Advisory for Multiple Products Under Its Brand
- Description:
- Forwarded from TWCERT/CC Security Advisory TWCERTCC-200-202609-00000019
- SAP released its September periodic update, which fixes a total of 20 vulnerabilities, 4 of which are high-risk security vulnerabilities (CVE-2026-44756, CVSS: 10.0, CVE-2026-58240, CVSS: 9.8, CVE-2026-76969, CVSS: 9.4, and CVE-2026-66768, CVSS: 9.0).
- CVE-2026-44756: A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker can exploit a specially crafted network request to cause undefined behavior and abnormal termination of the program.
- CVE-2026-58240: SAP NetWeaver Message Server performs insufficient authenticity verification of internal application server components during the registration process. An unauthenticated attacker with network access may perform unauthorized operations within the application environment.
- CVE-2026-76969: The @sap/cds-mtxs NPM library does not sufficiently check certain features used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker can exploit specially crafted requests to obtain sensitive credentials.
- CVE-2026-66768: SAP GUI for Java fails to properly enforce trust level policies for certain function calls from the connected backend system. A low-privilege attacker can exploit this vulnerability by manipulating the connected backend system to execute arbitrary commands on the victim's machine.
- Affected Platforms:
- SAP Extended Passport (EPP) Processing KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20 versions
- SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, 9.20 versions
- Specific versions of sap/cds-mtxs
- SAP NetWeaver (SAP GUI for Java) BC-FES-JAV 8.10 version
- Recommended Actions:
- Apply patches according to the resolution published on the official website https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html?isu_page=1
- References:
Computer and Communication Center
Network System Division