Summary
SAP released 20 security notes for September 2026, addressing four critical vulnerabilities including a CVSS 10.0 memory corruption flaw in Extended Passport Processing and a CVSS 9.8 authentication bypass in NetWeaver Message Server.
Take Action:
If you run SAP applications time to patch. Prioritize the critical fixes for Extended Passport/Web Dispatcher, the NetWeaver Message Server, the CAP sap/cds-mtxs credential leak, and SAP GUI for Java. Then go through the rest of the list. Until patching is complete, make sure the Web Dispatcher, Message Server and other SAP components are not reachable from the internet and are only accessible from trusted internal networks. Don't forget to also apply the updated note for ABAP Developer Tools.
Read the full article on BeyondMachines
This article was originally published on BeyondMachines
Top comments (1)
It’s concerning to see such critical vulnerabilities like the CVSS 10.0 memory corruption flaw and CVSS 9.8 authentication bypass in SAP's systems. Your emphasis on immediate patching and restricting access to vulnerable components is spot on—it's vital for any organization to prioritize security in these scenarios. One improvement could be implementing a regular security audit schedule alongside these updates to proactively identify potential risks. If you need assistance with security implementations or patches, I’d be glad to discuss a paid collaboration to help enhance your security posture. What strategies do you think would be most effective in managing these vulnerabilities in the long run?