[CIAD-2026-0045] Multiple Vulnerabilities in SAP Products

By Published On: September 10, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in SAP Products


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: High


Software Affected


SAP Extended Passport (EPP) Processing

SAP NetWeaver (Message Server)

SAP Cloud Application Programming Model (CAP)

SAP NetWeaver (SAP GUI for Java)

SAP ABAP Developer Tools

SAP Integration Suite

SAP NetWeaver Business Client

SAP NetWeaver Application Server for ABAP and ABAP Platform

SAP Commerce Cloud (Search And Navigation)

SAP Web Dispatcher, Internet Communication Manager and SAP Content Server

SAP S/4HANA (Intercompany Matching and Reconciliation)

SAP Manufacturing Integration and Intelligence

SAPUI5 (Frame Options Allowlist)

SAP S/4HANA (Finance for Advanced Payment Management)

SAP S/4HANA (Manage Bank Chains app)

SAP NetWeaver and ABAP Platform

SAP Process Integration (SOAP Adapter)

Overview


Multiple vulnerabilities have been reported in various SAP products which could allow a remote attacker to execute arbitrary code, elevate privileges, obtain sensitive information, bypass security restrictions, cause memory corruption, cause denial of service (DoS) conditions, gain unauthorized access, manipulate application data, and perform server-side request forgery (SSRF) on the targeted system.


Target Audience:

Users of SAP products.


Risk Assessment:

High risk of complete system compromise, unauthorized access, and denial of service.


Impact Assessment:

Potential for execute arbitrary code, elevate privileges, disclose sensitive information, and cause denial of service (DoS) conditions.


Description


SAP provides a wide range of enterprise software solutions, including application servers, integration suites, and business process management tools used to manage critical business operations.


These vulnerabilities exist in various SAP products due to memory corruption, missing authentication, credential disclosure, improper access control, XML external entity (XXE) vulnerabilities, insecure deserialization, injection flaws, security misconfigurations, and missing authorization checks. A remote attacker could exploit these vulnerabilities by sending specially crafted requests to the targeted systems.


Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code, elevate privileges, obtain sensitive information, bypass security restrictions, cause memory corruption, cause denial of service (DoS) conditions, gain unauthorized access, manipulate application data, and perform server-side request forgery (SSRF) on the targeted system.




Solution


Apply appropriate fixes as mentioned in SAP Security Advisory:  

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html


Vendor Information


SAP

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html


References


SAP

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html


CVE Name

CVE-2026-44756

CVE-2026-58240

CVE-2026-76969

CVE-2026-66768

CVE-2026-58243

CVE-2026-76958

CVE-2026-76967

CVE-2026-66767

CVE-2026-2332

CVE-2026-76968

CVE-2026-44766

CVE-2026-76971

CVE-2026-34477

CVE-2026-76977

CVE-2026-76960

CVE-2026-76961

CVE-2026-76959

CVE-2026-76962

CVE-2026-76963

CVE-2026-58234




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmqixTwACgkQ3jCgcSdc

ys85hBAAqD+PeK6kgFFJmIzNU+/jn4oFUUu+eFD0Lak/Zm8sLHCsGxcn47n7vSl/

JWRGx+qn5f+xh5rFo7A+lh55ht6e/QfE+XnrmVNKhgV5FawH0sfGdDKC/FEPz2jg

4OEuexFGtp4u6ERLqOERKDVQ09DriS1p6J8NN3fnzqnnoXMaz58gnalmeQphhcXn

mDtO9kQFNFT9jPHG+XSTcKvW9GUD8f4Y+sf/qUiLek7+jTI/HfyBI8XfL0YO9+Cp

hPQqGbkB03G0LL+j+sCqvCoUBp4lcB1TSIugNWGy5+oeWWWlRUuJWqDNu/UJVOwA

ubvOaW7VcE2Ghx17TqPk75Q9/2RwB7UB7mrrJf86UGJIzWtYGXawhqUBteeZ350u

a9IEflHWz9taA/UEtwzFELHDnT069sPoh4p/fTe2tE8LrI0QcayiNlOPR2DhTXFi

4T8TGaJXy/V9ioNv4Enx6tPmjX+JuWnxhN8DJb7Vh8B1VUt5tg6gQQg+/FdGD1O6

ScNKhB6/0BCrVrrETWBH0jARET3KVGVDthDge76syU13MrQUpxagIPrESY+DtgPX

c1JC68hoOBkO7Sx9jol/3VZh4302kJa2cugmNf9gwo60SQdDU/cdfhRLVTMKNBaR

OjCJEyjvOgqfbN8T9H/iwo31/IDTdPcsihzBOuPuPFliJMPZwXc=

=fFpb

—–END PGP SIGNATURE—–

Share this article