【Vulnerability Alert】SAP Issues Critical Cybersecurity Advisories for Multiple Products_20260918
Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026091808091414 | Publication Time | 2026-09-18 08:50:15 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026-09-18 08:50:15 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】SAP Issues Critical Cybersecurity Advisories for Multiple Products_20260918 |
|||
| [Content]
Forwarded from TWCERTCC Cybersecurity Alert TWCERTCC-200-202609-00000019 SAP released its September routine security updates, addressing a total of 20 vulnerabilities, including four high-risk security vulnerabilities (CVE-2026-44756, CVSS: 10.0; CVE-2026-58240, CVSS: 9.8; CVE-2026-76969, CVSS: 9.4; and CVE-2026-66768, CVSS: 9.0). CVE-2026-44756: A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker may exploit specially crafted network requests to cause undefined behavior and abnormal program termination. CVE-2026-58240: SAP NetWeaver Message Server provides insufficient authenticity verification for internal application server components during the registration process. An unauthenticated attacker with network access may be able to perform unauthorized operations within the application environment. CVE-2026-76969: The CVE-2026-66768: SAP GUI for Java does not properly enforce trust-level policies for certain function calls from connected backend systems. A low-privileged attacker may exploit this vulnerability by manipulating the connected backend system, resulting in the execution of arbitrary commands on the victim's machine. Information Sharing Level: WHITE (the intelligence content is information that may be publicly disclosed) |
|||
| [Affected Platform]
SAP Extended Passport (EPP) Processing KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20 versions SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, 9.20 versions Specific versions of sap/cds-mtxs SAP NetWeaver (SAP GUI for Java) BC-FES-JAV version 8.10 |
|||
|
[Recommended Actions] Apply the patches according to the remediation instructions released on the official website: |
|||
|
[Reference] |
|||
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw





