Skip to content
Threat Feed
high threat

SAP Security Updates - September 2026

Roundup of SAP security advisories published in September 2026.

CVE search metadata

CVE search record: CVE-2026-58240. Severity: critical. CVSS: 9.8. KEV: no. Product: NetWeaver Message Server. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/

CVE search record: CVE-2026-66768. Severity: critical. CVSS: 9.0. KEV: no. Product: SAP GUI for Java. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/

CVE search record: CVE-2026-76969. Severity: critical. CVSS: 9.4. KEV: no. Product: @sap/cds-mtxs. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/

CVE search record: CVE-2026-66767. Severity: high. CVSS: 7.7. KEV: no. Product: NetWeaver Application Server for ABAP. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/

CVE search record: CVE-2026-76958. Severity: high. CVSS: 8.5. KEV: no. Product: Integration Suite. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/

CVE search record: CVE-2026-76967. Severity: high. CVSS: 7.8. KEV: no. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/

What's new

This roundup covers 5 SAP security vulnerabilities. CVSS base scores range from 7.7 to 9.8. None are reported as actively exploited at the time of release. The issues affect @sap/cds-mtxs, Integration Suite, NetWeaver Application Server for ABAP, NetWeaver Message Server, SAP GUI for Java.

Summary

CVEProductSeverityCVSSEPSSKEVSource
CVE-2026-58240NetWeaver Message ServerCritical9.8noNVD (authoritative)
CVE-2026-66768SAP GUI for JavaCritical9.0noNVD (authoritative)
CVE-2026-76969@sap/cds-mtxsCritical9.4noNVD (authoritative)
CVE-2026-66767NetWeaver Application Server for ABAPHigh7.7noNVD (authoritative)
CVE-2026-76958Integration SuiteHigh8.5noNVD (authoritative)

CVE-2026-58240

SAP NetWeaver Message Server contains a vulnerability where it fails to properly validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access can exploit this to register unauthorized components, leading to potential unauthorized actions, data compromise, and system instability.

Affected products:

  • NetWeaver Message Server

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-58240

CVE-2026-66768

SAP GUI for Java fails to properly enforce trust level policies when handling requests from a backend system. A low-privileged attacker who compromises or manipulates the backend can trigger these functions to execute arbitrary commands on the client machine running SAP GUI, resulting in a full compromise of the local environment.

Affected products:

  • SAP GUI for Java

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-66768

CVE-2026-76969

The @sap/cds-mtxs NPM library contains a vulnerability in multitenant CAP applications where insufficient checks on extensibility functionality allow unauthenticated remote attackers to obtain sensitive credentials. These credentials can then be used to manipulate or delete tenant data, resulting in significant impact to data integrity and service availability.

Affected products:

  • @sap/cds-mtxs

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-76969

CVE-2026-66767

CVE-2026-66767 is a vulnerability in SAP NetWeaver Application Server for ABAP and the ABAP Platform that allows unauthenticated attackers to trigger the reprocessing of buffered user requests. By sending a specially crafted packet under specific timing conditions, an attacker can hijack another user's session, leading to significant impacts on data confidentiality and integrity.

Affected products:

  • NetWeaver Application Server for ABAP
  • ABAP Platform

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-66767

CVE-2026-76958

SAP Integration Suite is vulnerable to an XML External Entity (XXE) injection flaw due to insufficient validation of XML documents from untrusted sources. An attacker with low privileges can exploit this to read sensitive files from the server, exfiltrating the contents via monitoring or logging outputs, or cause a denial-of-service condition through resource exhaustion.

Affected products:

  • Integration Suite

Source: https://nvd.nist.gov/vuln/detail/CVE-2026-76958