On September 8, 2026, SAP released its monthly Security Patch Day, and it is one of the most serious of the year: two vulnerabilities scored the maximum CVSS 10.0 and a third scored 9.8 in the SAP NetWeaver Message Server. Here is a summary of the most critical notes, the affected systems and where to start patching.
By the numbers
Counts differ by source depending on whether updated notes are included. Onapsis reports 22 security notes, including 5 HotNews and 6 High priority. Pathlock counts 33 notes (19 new, 14 updated). The official source is SAP’s Security Notes page for September 2026.
Most critical notes
| Note | CVE | CVSS | Product | Issue |
|---|---|---|---|---|
| 3747649 | CVE-2026-44756 | 10.0 | SAP Kernel (Extended Passport, EPP) | Memory corruption in EPP processing, exploitable remotely without authentication |
| 3771065 | CVE-2026-58231 | 10.0 | SAP Commerce Cloud | Authorization flaw enabling unauthenticated remote code execution |
| 3759472 | CVE-2026-58240 | 9.8 | SAP NetWeaver Message Server | Insufficient validation during component registration: rogue nodes could join the cluster |
| 3798315 | CVE-2026-76969 | 9.4 | SAP Cloud Application Programming Model (CAP) | Credential exposure in multitenant applications |
Pathlock also highlights note 3781729 (CVSS 9.0, SAP GUI for Java), a trust-level bypass that allows command execution on user workstations, and note 3772411 (CVSS 8.8), an authorization bypass in the ABAP Development Tools SQL Console.
Why this month is serious
- Core components: the Kernel and Message Server run in virtually every SAP NetWeaver and on-premise S/4HANA system.
- No credentials needed: the most severe flaws are exploitable remotely without authentication.
- Commerce Cloud has several notes this cycle, so e-commerce teams need a dedicated patch window.
Patching priorities
- Inventory systems with affected Kernel versions, Web Dispatcher and exposed Message Servers.
- Kernel and Message Server first (notes 3747649 and 3759472).
- Commerce Cloud (note 3771065) if you run SAP Commerce.
- Multitenant CAP applications on SAP BTP (note 3798315).
- Clients: update SAP GUI for Java where it is used.
- Until patched, restrict network access to the Message Server and system ports to required sources only.
ABAP corrections are implemented with transaction SNOTE; Kernel fixes require a Kernel update. See also our SAP tables list for Basis tables such as E070 and TADIR.
What is SAP Security Patch Day?
SAP publishes its security notes on the second Tuesday of every month. Notes are prioritized by CVSS score: HotNews (9.0–10.0), High (7.0–8.9), Medium and Low. We will publish a summary every month.
FAQ
When is the next SAP Security Patch Day?
The second Tuesday of October 2026: October 13.
Does it affect SAP S/4HANA Cloud Public Edition?
In SAP-managed cloud editions, SAP applies the patches. Kernel and Message Server notes mainly affect on-premise systems and Private Edition depending on the operating model.
