SAP has closed several highly dangerous security holes on its September patch day – including a flaw rated at the maximum CVSS 10.0 that lets attackers run commands with SAP administrator privileges without any login.
The Walldorf-based group released 19 new security notes plus one update on 8 September 2026. It rates four of them as critical. The affected components sit at the core of NetWeaver, S/4HANA and the SAP Cloud, running in nearly every large enterprise network.
Maximum score for the Extended Passport flaw
The most severe issue is CVE-2026-44756 (CVSS 10.0, SAP Security Note 3747649) in the SAP kernel’s Extended Passport Protocol. An unauthenticated attacker sends a malformed protocol header that triggers a memory overflow. According to SAP security specialist Onapsis, the flaw can be exploited remotely and without credentials, allowing arbitrary operating-system commands to be run with SAP administrative privileges on the host – a full system takeover.
Message Server accepts rogue components
Almost as critical is CVE-2026-58240 (CVSS 9.8, Note 3759472) in the NetWeaver Message Server. Because it fails to properly validate the authenticity of internal application-server components during registration, network attackers can register their own malicious components. Onapsis says this affects every S/4HANA 2025 system and older installs running kernels 9.16 to 9.20. Further critical notes:
- CVE-2026-76969 (CVSS 9.4): credential theft in multitenant cloud applications (sap/cds-mtxs)
- CVE-2026-66768 (CVSS 9.0): improper access restriction
- CVE-2026-58243 (CVSS 8.8): missing authorization check
No active attacks have been reported so far. Both top flaws carry the HotNews label, however, and message servers exposed to the internet or poorly segmented are considered particularly at risk. Administrators should apply the patches across all environments immediately.
Sources: Onapsis · SecurityOnline · Cyber Security News



















