SAP Security Notes Summary – September 2026
After a break, I am returning to my monthly SAP Security Notes summaries. Below you will find an overview of SAP Security Notes released or updated in September 2026, with SAP’s recommendations on security patches and actions to help protect your systems.
| SAP Component | Number | Title | CVSS Score | Released On |
|---|---|---|---|---|
| CA-DMS-OP | 3678417 | [CVE-2026-0505] Multiple vulnerabilities in BSP Applications of SAP Document Management System | 6,1 | 22.09.2026 |
| CA-FLP-FE-COR | 3680888 | [CVE-2026-76974] Information Disclosure vulnerability in SAP Fiori Launchpad | 5,3 | 22.09.2026 |
| CA-ATP-SUP | 3485073 | [CVE-2026-66766] Denial of Service (DoS) due to use of third-party component in SAP S/4HANA (Manage Supply Protection) | 7,5 | 22.09.2026 |
| BC-I18 | 3772838 | [CVE-2026-76963] Missing Authorization Check in Application Server ABAP of SAP NetWeaver and ABAP Platform | 4,3 | 08.09.2026 |
| FI-BL-MD | 3657599 | [CVE-2026-76962] Missing Authorization check in SAP S/4HANA (Manage Bank Chains app) | 4,3 | 08.09.2026 |
| FIN-FSCM-PF | 3371336 | [CVE-2026-76961] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) | 4,3 | 08.09.2026 |
| FIN-FSCM-PF | 3365276 | [CVE-2026-76960] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) | 4,3 | 08.09.2026 |
| FIN-FSCM-PF | 3365311 | [CVE-2026-76959] Cross-Site Request Forgery (CSRF) vulnerability in SAP S/4HANA (Finance for Advanced Payment Management) | 4,3 | 08.09.2026 |
| BC-XS-CDX-SEC | 3798315 | [CVE-2026-76969] Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP) | 9,4 | 08.09.2026 |
| BC-XI-CON-SOP | 3736494 | [CVE-2026-58234] Denial of Service vulnerability in SAP Process Integration(SOAP Adapter) | 2,2 | 08.09.2026 |
| LOD-HCI-PI-TPM | 3792978 | [CVE-2026-76958] XML External Entity (XXE) Vulnerability in SAP Integration Suite | 8,5 | 08.09.2026 |
| CEC-SCC-COM-SRC-SER | 3791068 | [CVE-2026-2332] CLRF Injection vulnerability due to use of Jetty components in SAP Commerce Cloud (Search And Navigation) | 7,4 | 08.09.2026 |
| CEC-SCC-COM-SRC-SER | 3787345 | [CVE-2026-34477] Security Misconfiguration vulnerability due to use of Apache Log4j in SAP Commerce Cloud (Search and Navigation) | 5,9 | 08.09.2026 |
| MFG-MII-CON | 3786489 | [CVE-2026-76971] Server-Side Request Forgery in SAP Manufacturing Integration and Intelligence | 6,5 | 08.09.2026 |
| BC-FES-BUS | 3784138 | [CVE-2026-76967] Insecure Deserialization in SAP NetWeaver Business Client | 7,8 | 08.09.2026 |
| CA-UI5-COR | 3783189 | [CVE-2026-76977] Clickjacking vulnerability in SAPUI5(Frame Options Allowlist) | 4,3 | 08.09.2026 |
| BC-FES-JAV | 3781729 | [CVE-2026-66768] Improper Access Control in SAP NetWeaver (SAP GUI for Java) | 9,0 | 08.09.2026 |
| BC-DWB-AIE-DP | 3772411 | [CVE-2026-58243] Privilege Escalation vulnerability in SAP ABAP Developer Tools | 8,8 | 08.09.2026 |
| BC-CST-MS | 3759472 | [ CVE-2026-58240] Missing Authentication check in SAP NetWeaver (Message Server) | 9,8 | 08.09.2026 |
| BC-MID-RFC | 3757002 | [CVE-2026-66767] Memory Corruption vulnerability in SAP NetWeaver Application Server for ABAP and ABAP Platform | 7,7 | 08.09.2026 |
| FIN-CS-ICR | 3756450 | [CVE-2026-44766] – SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation) | 6,5 | 08.09.2026 |
| BC-CST-IC | 3750721 | [CVE-2026-76968] Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server | 6,5 | 08.09.2026 |
| BC-CST-DP | 3747649 | [CVE-2026-44756] Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing | 10,0 | 08.09.2026 |
CVSS (Common Vulnerability Scoring System) expresses the severity of a vulnerability as a numerical score. Use it alongside the affected products and your environment when prioritizing security corrections.
Source: SAP for Me – Security Notes. Access to the full notes requires an SAP login.
