SAP Security Notes, September 2026

SAP Security Note 3747649 addresses a critical security vulnerability in SAP Extended Passport (EPP) processing that could allow an attacker to send a specially crafted network request and potentially cause affected SAP systems to crash and disrupt system operations. Because the vulnerability can be exploited remotely without requiring a user to log in, SAP has assigned it the highest severity rating (CVSS 10.0) and recommends prompt remediation. The issue affects SAP NetWeaver AS ABAP and Java systems running vulnerable kernel versions, as well as SAP Web Dispatcher 9.16. SAP has released kernel and Web Dispatcher patches to correct the root cause of the issue. For organizations that cannot patch immediately, SAP provides a temporary workaround for certain HTTP(S)-based scenarios using SAP Web Dispatcher, although this does not fully protect against all attack methods. Given its severity and the potential impact on system availability and security, this note should be treated as a high-priority patching requirement.

SAP Security Note 3759472 addresses a critical security vulnerability (CVSS 9.8) in the SAP NetWeaver Message Server that could allow an attacker with network access to connect an unauthorized server component to an SAP environment without authentication. Once connected, the attacker could potentially gain unauthorized access to system functions and impact the security and availability of the affected SAP landscape. SAP has corrected the issue by strengthening the verification process used when server components connect to the Message Server. Because the vulnerability can be exploited remotely, requires no authentication, and has no available workaround, SAP recommends that affected customers apply the required kernel patches as soon as possible and treat this note as a high-priority security update.

SAP Security Note 3798315 addresses a critical vulnerability (CVSS 9.4) in certain multi-tenant applications built with the SAP Cloud Application Programming Model (CAP). SAP identified a weakness that could allow an attacker to gain access to sensitive credentials used by affected applications and potentially use those credentials to modify, delete, or disrupt customer data. The issue affects CAP applications that use vulnerable versions of the @sap/cds-mtxs library and have extensibility features enabled. SAP has released updated versions of the affected software components and recommends that customers upgrade immediately and redeploy their applications. For customers running on SAP BTP Cloud Foundry, SAP has already taken additional steps to block the affected application endpoints until they are patched. Due to the potential impact on customer data and application availability, organizations using multitenant CAP applications should review this note promptly and apply the recommended updates as a high priority.

SAP Security Note 3781729 addresses a critical vulnerability (CVSS 9.0) in SAP GUI for Java that could allow a user with limited access to an SAP system to exploit a weakness in how trust settings are enforced. Under certain conditions, the vulnerability could be used to run unauthorized commands on a user’s workstation when interacting with an untrusted SAP system, potentially leading to compromise of the affected device and its data. SAP has released a patch that improves the way SAP GUI for Java validates trusted and untrusted systems before allowing certain actions. Because there is no workaround available, customers using SAP GUI for Java 8.10 should apply the recommended patch as soon as possible. For most organizations, the primary risk is to end-user workstations that connect to untrusted or potentially compromised SAP systems.

Share the Post: