SOCLYDE logo
Current languageEN
Cybersecurity newsSAPSAP NetWeaverCritical vulnerability

Sap kernel and netweaver: two critical flaws to patch in september 2026

SAP’s September 8, 2026 Security Patch Day fixes two critical Kernel and NetWeaver vulnerabilities, including a CVSS 10.0 issue exploitable without authentication.

By Soclyde Team

Technician checking a maintenance folder in an industrial warehouse

In summary

  • On September 8, 2026, SAP published 19 new security notes, including two critical fixes for Kernel EPP processing and the NetWeaver Message Server.
  • CVE-2026-44756 has a CVSS score of 10.0 and CVE-2026-58240 a score of 9.8; CERT-EU describes both as remotely exploitable without authentication based on the published information.
  • SAP teams should identify affected versions, apply SAP Notes 3747649 and 3759472, then review exposure and the technical accounts connected to the affected systems.

Explore next

Soclyde resources

Article contents

On September 8, 2026, SAP published its monthly Security Patch Day with 19 new security notes and one update. Two critical flaws directly affect the Kernel and the SAP NetWeaver Message Server: CVE-2026-44756, a memory corruption vulnerability in Extended Passport (EPP) processing, and CVE-2026-58240, a missing authentication check in the Message Server.

Their severity is high: SAP assigns CVSS 10.0 to CVE-2026-44756 and 9.8 to CVE-2026-58240. CERT-EU describes both as remotely exploitable without authentication based on the published information. Administrators should therefore treat the notes as a patching priority without assuming facts about a particular instance.

What SAP published on September 8

SAP’s official Security Patch Day page lists the products, notes and affected versions. SAP Note 3747649 fixes CVE-2026-44756 in Kernel components and related components; Note 3759472 fixes CVE-2026-58240 in Kernel versions used by the SAP NetWeaver Message Server. The exact scope depends on the installed version and active components.

The same bulletin lists other critical vulnerabilities, including issues in SAP GUI for Java and the multitenant CAP library. This article focuses on the two Kernel/NetWeaver flaws that can affect the execution layer and message service of an SAP landscape.

Two mechanisms, two attack paths

CVE-2026-44756 is a memory corruption vulnerability in SAP Extended Passport processing. Public sources describe it as potentially enabling unauthenticated remote command execution on affected configurations. The presence of a product or version in SAP’s list does not by itself establish that a particular instance is Internet-accessible.

CVE-2026-58240 is an authentication-check failure in the SAP NetWeaver Message Server. CERT-EU and Onapsis report that an unauthenticated remote attacker could exploit it to register unauthorized components and perform actions in the affected landscape. The topology, network rules and SAP settings determine the path that is actually available.

Why this is an operational priority

An SAP server brings together business processes, data and technical identities. Compromise of the Kernel or Message Server does not automatically mean that every business record was accessed; it can nevertheless turn a technical defect into an availability, integrity or confidentiality incident. Assessment must start from versions, exposed interfaces, logs and installation privileges.

CVSS helps prioritize, but it does not replace inventory. Teams must distinguish a theoretically affected version from a service that is actually loaded, reachable and unpatched. That avoids both underestimating the exposure window and announcing a compromise that has not been observed.

What SAP teams should check

Start by inventorying Kernel versions, NetWeaver instances, the Message Server, Web Dispatcher and any EPP components in use. Compare that inventory with the fixed versions in SAP Notes 3747649 and 3759472, then schedule the patches with system owners and business teams.

At the same time, review exposed ports and interfaces, administrative access, recent changes and authentication logs. Look for unexpected registrations, added components, unusual commands and connections from unplanned sources. If an indicator of compromise appears, preserve evidence and activate the incident response process before cleaning the environment.

Technical secrets after an urgent patch

An SAP patch campaign is not limited to replacing binaries. Teams should also know which service accounts, keys and passwords are used by operating systems, interfaces, monitoring tools and vendors. A secret shared across integrations makes revocation broader and investigation less certain.

Assign a distinct secret to each use, tie it to an owner and document its rotation procedure. Do not leave these credentials in an uncontrolled deployment file or shared note. Patching the vulnerability and rotating secrets are separate actions: one reduces the software defect, while the other limits possible persistence from an access already obtained.

Soclyde does not patch SAP Kernel, NetWeaver or enterprise infrastructure, and it cannot determine whether an instance was compromised. Its role is narrower: help a small team generate a unique secret for each technical access, store it in a local-first encrypted vault and quickly retrieve the information needed during a rotation.

This organization reduces secret reuse and makes access review easier after urgent maintenance. It complements SAP patches, segmentation, monitoring and incident response; it does not replace them. To structure your access inventory, read our secure password generator guide or contact Soclyde.

Key takeaways

SAP’s September 8, 2026 Security Patch Day fixes two critical flaws affecting the Kernel and the NetWeaver Message Server. CVE-2026-44756 is rated CVSS 10.0 and CVE-2026-58240 CVSS 9.8; public sources describe both as remotely exploitable without authentication. The priority is to check deployed versions, apply the relevant SAP notes and look for signs of unexpected access.

After patching, inventory technical accounts and rotate secrets that may have been exposed. For a practical next step, read our secure password generator guide or talk to Soclyde.

Frequently asked questions

What are the two critical SAP flaws from September 2026?

CVE-2026-44756 is a memory corruption vulnerability in SAP Extended Passport (EPP) processing in the Kernel, scored CVSS 10.0. CVE-2026-58240 is a missing authentication check in the SAP NetWeaver Message Server, scored CVSS 9.8. Use SAP Notes 3747649 and 3759472 to map the exact scope to your version.

Can these vulnerabilities be exploited without a SAP account?

CERT-EU describes both as remotely exploitable without authentication and reports that successful exploitation could lead to operating-system command execution under the SAP installation account. That description does not replace an assessment of your architecture, exposed interfaces and deployed versions.

What if an SAP instance cannot be patched immediately?

Prioritize instance qualification and apply the SAP notes. Until then, reduce network exposure of the affected components using SAP-validated procedures, monitor logs and prepare rotation of technical secrets if compromise is suspected. A compensating control must not be presented as a patch.

References

Sources and references

Need advice?

Design your password strategy with Soclyde

Schedule a dedicated walkthrough with the team to see how local-first security adapts to your stack.

Talk with us

Keep reading