SAP Security Updates - September 2026
Roundup of SAP security advisories published in September 2026.
CVE search metadata
CVE search record: CVE-2026-58240. Severity: critical. CVSS: 9.8. KEV: no. Product: NetWeaver Message Server. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/
CVE search record: CVE-2026-66768. Severity: critical. CVSS: 9.0. KEV: no. Product: SAP GUI for Java. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/
CVE search record: CVE-2026-76969. Severity: critical. CVSS: 9.4. KEV: no. Product: @sap/cds-mtxs. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/
CVE search record: CVE-2026-66767. Severity: high. CVSS: 7.7. KEV: no. Product: NetWeaver Application Server for ABAP. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/
CVE search record: CVE-2026-76958. Severity: high. CVSS: 8.5. KEV: no. Product: Integration Suite. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/
CVE search record: CVE-2026-76967. Severity: high. CVSS: 7.8. KEV: no. Brief: SAP Security Updates - September 2026. Brief link: https://feed.craftedsignal.io/briefs/2026-09-sap-security-updates/
What's new
This roundup covers 5 SAP security vulnerabilities. CVSS base scores range from 7.7 to 9.8. None are reported as actively exploited at the time of release. The issues affect @sap/cds-mtxs, Integration Suite, NetWeaver Application Server for ABAP, NetWeaver Message Server, SAP GUI for Java.
Summary
| CVE | Product | Severity | CVSS | EPSS | KEV | Source |
|---|---|---|---|---|---|---|
| CVE-2026-58240 | NetWeaver Message Server | Critical | 9.8 | no | NVD (authoritative) | |
| CVE-2026-66768 | SAP GUI for Java | Critical | 9.0 | no | NVD (authoritative) | |
| CVE-2026-76969 | @sap/cds-mtxs | Critical | 9.4 | no | NVD (authoritative) | |
| CVE-2026-66767 | NetWeaver Application Server for ABAP | High | 7.7 | no | NVD (authoritative) | |
| CVE-2026-76958 | Integration Suite | High | 8.5 | no | NVD (authoritative) |
CVE-2026-58240
SAP NetWeaver Message Server contains a vulnerability where it fails to properly validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access can exploit this to register unauthorized components, leading to potential unauthorized actions, data compromise, and system instability.
Affected products:
- NetWeaver Message Server
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-58240
CVE-2026-66768
SAP GUI for Java fails to properly enforce trust level policies when handling requests from a backend system. A low-privileged attacker who compromises or manipulates the backend can trigger these functions to execute arbitrary commands on the client machine running SAP GUI, resulting in a full compromise of the local environment.
Affected products:
- SAP GUI for Java
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-66768
CVE-2026-76969
The @sap/cds-mtxs NPM library contains a vulnerability in multitenant CAP applications where insufficient checks on extensibility functionality allow unauthenticated remote attackers to obtain sensitive credentials. These credentials can then be used to manipulate or delete tenant data, resulting in significant impact to data integrity and service availability.
Affected products:
- @sap/cds-mtxs
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-76969
CVE-2026-66767
CVE-2026-66767 is a vulnerability in SAP NetWeaver Application Server for ABAP and the ABAP Platform that allows unauthenticated attackers to trigger the reprocessing of buffered user requests. By sending a specially crafted packet under specific timing conditions, an attacker can hijack another user's session, leading to significant impacts on data confidentiality and integrity.
Affected products:
- NetWeaver Application Server for ABAP
- ABAP Platform
Source: https://nvd.nist.gov/vuln/detail/CVE-2026-66767
CVE-2026-76958
SAP Integration Suite is vulnerable to an XML External Entity (XXE) injection flaw due to insufficient validation of XML documents from untrusted sources. An attacker with low privileges can exploit this to read sensitive files from the server, exfiltrating the contents via monitoring or logging outputs, or cause a denial-of-service condition through resource exhaustion.
Affected products:
- Integration Suite