SAP Security Notes: September 2026 Patch Day

Share

Critical vulnerabilities in SAP Kernel (OVERPASS) and S/4HANA (S4GET) patched in collaboration with the Onapsis Research Labs

On Wednesday, September 9th at 10:00am EDT, SAP and the Onapsis Research Labs will host a joint threat briefing webinar to discuss these vulnerabilities and the other critical vulnerabilities patched as part of the September 2026 SAP Patch Tuesday release. Register here

Highlights of September SAP Security Notes analysis include:

  • September Summary Twenty-two new and updated SAP security patches released, including five HotNews Notes and six High Priority Notes 
  • Critical SAP Kernel vulnerability – Multiple critical aspects of the vulnerability require immediate patching
  • Onapsis Research Labs Contribution Our team supported SAP in patching eight vulnerabilities covered by six SAP Security Notes, including three tagged as HotNews 

SAP has published twenty-two new and updated SAP Security Notes in its September Patch Day, including five HotNews Notes and six High Priority Notes. Six of the twenty new Security Notes were published in contribution with the Onapsis Research Labs.  

The HotNews Notes in Detail

The Onapsis Research Labs (ORL) supported SAP in patching several critical vulnerabilities.

SAP Security Note #3747649, tagged with a CVSS score of 10.0, patches a Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing, which the Onapsis Research Labs is dubbing OVERPASS. The ORL team discovered that boundary validation is missing during the deserialization of EPP data resulting in a memory safety violation when processing externally supplied length fields. This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application. The SAP Security Note provides a patch for ABAP and Java kernels and for SAP Web Dispatcher, version 9.16. Other Web Dispatcher versions and Web Dispatcher as part of SAP HANA Extended Application Services are not affected. We recommend immediate patching since the vulnerability:

  • Is exploitable remotely and without authentication
  • Exists by default in a wide range of SAP technology components
  • Allows remote attackers to run arbitrary operating system commands on the SAP host with SAP administrative privileges, resulting in full compromise of the underlying SAP business data and processes;
  • It is reachable through several SAP components and several communication protocols, none of them requiring credentials, so no single network control can fully mitigate risk.

More information on the OVERPASS vulnerability can be found here.

SAP Security Note #3771065, tagged with a CVSS score of 10.0, contains an update for the critical SAP Commerce Cloud (Data Hub Adapter) that was initially released lately on SAP’s August Patch Day. The updated note points out that unmodified SAP Commerce Cloud environments are not exposed to the Improper Authorization vulnerability by default and provides an FAQ document to verify the setup.

SAP Security Note #3759472, tagged with a CVSS score of 9.8, was also published in collaboration with the ORL team. They discovered that the SAP NetWeaver Message Server insufficiently validates the authenticity of internal application server components during registration. Consequently, unauthenticated attackers with network access can register unauthorized components and potentially perform unauthorized actions within the application environment. A successful exploitation could result in a high impact on the confidentiality, integrity, and availability of the affected system. The vulnerability, which the Onapsis Research Labs is dubbing S4GET,  is present across SAP’s entire modern kernel family (9.16, 9.18, 9.19, 9.20), meaning every S/4HANA 2025 system and any earlier release already moved to one of those kernels is affected.

Details about the S4GET vulnerability and the involved risks can be found here.  

A Credential Disclosure vulnerability in multitenant applications using SAP Cloud Application Programming Model (CAP), is patched with SAP Security Note #3798315, tagged with a CVSS score of 9.4. The vulnerability exists in a specific NPM library and allows an unauthenticated attacker  to obtain sensitive credentials by sending specially crafted requests. These credentials can be used afterwards to replace or delete tenant data resulting in a high impact on availability and integrity of the application and partial impact to the confidentiality of business data. Customers on SAP Cloud Foundry will no longer be able to change tenant-level extensions for unpatched applications. There is a workaround available for customers not on Cloud Foundry that is described in more detail in FAQ note #3802171.

The third HotNews Notes that is published in collaboration with the ORL team on SAP’s September Patch Day is SAP Security Note #3781729, tagged with a CVSS score of 9.0. The team detected that SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. Through manipulation of a connected system they were able to trigger the affected functionality as a low-privileged user. A successful exploitation allows the execution of arbitrary commands on the victim’s machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system.

The High Priority Notes in Detail

SAP Security Note #3772411, tagged with a CVSS score of 8.8, was initially released on SAP’s August Patch Day and patches a Privilege Escalation vulnerability in SAP ABAP Developer Tools. The note was updated with a minor text change.

SAP Security Note #3792978, tagged with a CVSS score of 8.5, patches an XML External Entity (XXE) vulnerability in SAP Integration Suite. Some components of the application do not sufficiently validate XML documents accepted from untrusted sources. This allows a low-privileged attacker to submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation allows reading sensitive file contents from the server and exposing them through monitoring or logging output, resulting in a high impact on confidentiality. It could also result in low impact on availability through resource exhaustion. Depending on which of the components are used, different iFlow packages have to be upgraded. Scenarios that intentionally rely on XML external entities or DTD features in XML processing may be negatively affected after upgrading since external entity resolution has been explicitly disabled with the patched iFLow packages.

SAP Security Note #3784138, tagged with a CVSS score of 7.8, affects SAP NetWeaver Business Client. Due to an insufficient validation of certain locally stored data during application startup, a low-privileged attacker on the local system could replace this data with specially crafted content. Upon next launch, the crafted content is processed and could lead to arbitrary code execution in the context of the user.        

SAP Security Note #3757002, tagged with a CVSS score of 7.7, patches a Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform. The vulnerability exists in the SAP kernel and allows an unauthenticated user to send a specially crafted packet that triggers reprocessing of a previously buffered user request, potentially hijacking another user’s session under narrow timing conditions. A successful exploitation requires an unauthenticated user request to coincide with a legitimate buffered request and could result in high impact on confidentiality and integrity, with low impact on availability of the application. 

SAP Security Note #3485073, tagged with a CVSS score of 7.4, was published on August, 25. It patches a Denial of Service vulnerability in a third-party component used by SAP S/4HANA (Manage Supply Protection). The third-party component suffers from a Regular Expression Denial of Service (ReDoS) vulnerability allowing unauthenticated attackers to trigger excessive processing within the affected functionality leading to a complete unavailability of the service.

SAP Security Note #3791068, tagged with a CVSS score of 7.4, patches a CLRF Injection vulnerability in SAP Commerce Cloud (Search And Navigation). The application uses a version of the Jetty components that could be vulnerable to CVE-2026-2332. The Jetty parser incorrectly terminated chunk extension parsing at a specific sequence of control characters even when that sequence appeared inside a quoted string, rather than treating it as a parse error. This allowed a specially crafted request with an unclosed quoted chunk extension to smuggle a second HTTP request, which Jetty processed as a separate legitimate request while the upstream proxy considered it part of the original request body. 

Onapsis Contribution

In addition to the three HotNews Notes, the Onapsis Research Labs (ORL) supported SAP in patching three Medium Priority vulnerabilities, all tagged with a CVSS score of 6.5.

SAP Security Note #3756450 patches an SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation). The team was able to access sensitive information by injecting malicious input into certain functions, which was processed by the database without proper validation. The patch improves the sanitization of user input by filtering disallowed keywords. 

SAP Security Note #3786489 addresses a Server-Side Request Forgery vulnerability in SAP Manufacturing Integration and Intelligence (SAP MII). The vulnerability enables an attacker to cause the server to initiate arbitrary outbound requests. The processing of these requests could be combined with XML/XSL processing to enable execution of scripts. The note does not provide automatic correction instructions but provides a list of nine manual activities that should be processed to harden the application.

SAP Security Note #3750721 patches an Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server. When authenticated as a low-privileged user, the ORL team was able to access certain administrative functionality and obtain sensitive information about the system state, resulting in information disclosure. This disclosed information could potentially be used in subsequent attacks.   

Summary & Conclusions

With twenty-two SAP Security Notes, SAP’s September Patch Day looks like an average one. But the four new HotNews Notes and six High Priority Notes convert it into a special one. Especially the new CVSS 10.0 note requires special attention because it can be exploited remotely and without authentication.

SAP NoteTypeDescriptionPriorityCVSS
3747649New[CVE-2026-44756] Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
BC-CST-DP
HotNews10
3771065Update[CVE-2026-58231] Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
CEC-SCC-PLA-PL
HotNews10
3759472New[CVE-2026-58240] Missing Authentication check in SAP NetWeaver (Message Server)
BC-CST-MS
HotNews9.8
3798315New[CVE-2026-76969] Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)
BC-XS-CDX-SEC
HotNews9.4
3781729New[CVE-2026-66768] Improper Access Control in SAP NetWeaver (SAP GUI for Java)
BC-FES-JAV
HotNews9
3772411Update[CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools
BC-DWB-AIE-DP
High8.8
3792978New[CVE-2026-76958] XML External Entity (XXE) Vulnerability in SAP Integration Suite
LOD-HCI-PI-TPM
High8.5
3784138New[CVE-2026-76967] Insecure Deserialization in SAP NetWeaver Business Client
BC-FES-BUS
High7.8
3757002New[CVE-2026-66767] Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform
BC-MID-RFC
High7.7
3485073New[CVE-2026-66766] Denial of Service (DoS) due to use of third-party component in SAP S/4HANA (Manage Supply Protection)
CA-ATP-SUP
High7.5
3791068New[CVE-2026-2332] CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation)
CEC-SCC-COM-SRC-SER
High7.4
3786489New[CVE-2026-76971] Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence
MFG-MII-CON
Medium6.5
3756450New[CVE-2026-44766] – SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation)
FIN-CS-ICR
Medium6.5
3750721New[CVE-2026-76968] Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server
BC-CST-IC
Medium6.5
3787345New[CVE-2026-34477] Security Misconfiguration vulnerability due to use of Apache Log4j in SAP Commerce Cloud (Search and Navigation)
CEC-SCC-COM-SRC-SER
Medium5.9
3772838New[CVE-2026-76963] Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform
BC-I18
Medium4.3
3657599New[CVE-2026-76962] Missing Authorization check in SAP S/4HANA (Manage Bank Chains app)
FI-BL-MD
Medium4.3
3371336New[CVE-2026-76961] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
FIN-FSCM-PF
Medium4.3
3365276New[CVE-2026-76960] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
FIN-FSCM-PF
Medium4.3
3365311New[CVE-2026-76959] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management)
FIN-FSCM-PF
Medium4.3
3783189New[CVE-2026-76977] Clickjacking vulnerability in SAPUI5(Frame Options Allowlist)
CA-UI5-COR
Medium4.3
3736494New[CVE-2026-58234] Denial of Service vulnerability in SAP Process Integration(SOAP Adapter)
BC-XI-CON-SOP
Low2.2

As always, the Onapsis Research Labs is already updating The Onapsis Platform to incorporate the newly published vulnerabilities into the product so that our customers can protect their businesses.

For more information about the latest SAP security issues and our continuous efforts to share knowledge with the security community, subscribe to our monthly Defender’s Digest Onapsis Newsletter.