【Vulnerability Alert】SAP Issues Critical Cybersecurity Advisories for Multiple Products_20260918

publish date : 2026-09-30 update date : 2026-10-02

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026091808091414 Publication Time 2026-09-18 08:50:15
Incident Type ANA-Vulnerability Alert Discovery Time 2026-09-18 08:50:15
Impact Level Low  
[Subject]
【Vulnerability Alert】SAP Issues Critical Cybersecurity Advisories for Multiple Products_20260918
[Content]

Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000019

SAP released its September routine security updates, addressing a total of 20 vulnerabilities, including four high-risk security vulnerabilities (CVE-2026-44756, CVSS: 10.0; CVE-2026-58240, CVSS: 9.8; CVE-2026-76969, CVSS: 9.4; and CVE-2026-66768, CVSS: 9.0).

CVE-2026-44756: A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker may exploit specially crafted network requests to cause undefined behavior and abnormal program termination.

CVE-2026-58240: SAP NetWeaver Message Server provides insufficient authenticity verification for internal application server components during the registration process. An unauthenticated attacker with network access may be able to perform unauthorized operations within the application environment.

CVE-2026-76969: The @sap/cds-mtxs NPM library does not adequately validate certain functions used in extensibility-enabled multitenant CAP applications. An unauthenticated attacker may exploit specially crafted requests to obtain sensitive credentials.

CVE-2026-66768: SAP GUI for Java does not properly enforce trust-level policies for certain function calls from connected backend systems. A low-privileged attacker may exploit this vulnerability by manipulating the connected backend system, resulting in the execution of arbitrary commands on the victim's machine.

Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed)

[Affected Platform]

SAP Extended Passport (EPP) Processing KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20 versions

SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, 9.20 versions

Specific versions of sap/cds-mtxs

SAP NetWeaver (SAP GUI for Java) BC-FES-JAV version 8.10

[Recommended Actions]

Apply the patches according to the remediation instructions released on the official website:

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html?isu_page=1

[Reference]

 https://www.twcert.org.tw/tw/cp-169-11207-b9e4b-1.html

(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center