On September 8, 2026, SAP published its monthly Security Patch Day with 19 new security notes and one update. Two critical flaws directly affect the Kernel and the SAP NetWeaver Message Server: CVE-2026-44756, a memory corruption vulnerability in Extended Passport (EPP) processing, and CVE-2026-58240, a missing authentication check in the Message Server.
Their severity is high: SAP assigns CVSS 10.0 to CVE-2026-44756 and 9.8 to CVE-2026-58240. CERT-EU describes both as remotely exploitable without authentication based on the published information. Administrators should therefore treat the notes as a patching priority without assuming facts about a particular instance.
What SAP published on September 8
SAP’s official Security Patch Day page lists the products, notes and affected versions. SAP Note 3747649 fixes CVE-2026-44756 in Kernel components and related components; Note 3759472 fixes CVE-2026-58240 in Kernel versions used by the SAP NetWeaver Message Server. The exact scope depends on the installed version and active components.
The same bulletin lists other critical vulnerabilities, including issues in SAP GUI for Java and the multitenant CAP library. This article focuses on the two Kernel/NetWeaver flaws that can affect the execution layer and message service of an SAP landscape.
Two mechanisms, two attack paths
CVE-2026-44756 is a memory corruption vulnerability in SAP Extended Passport processing. Public sources describe it as potentially enabling unauthenticated remote command execution on affected configurations. The presence of a product or version in SAP’s list does not by itself establish that a particular instance is Internet-accessible.
CVE-2026-58240 is an authentication-check failure in the SAP NetWeaver Message Server. CERT-EU and Onapsis report that an unauthenticated remote attacker could exploit it to register unauthorized components and perform actions in the affected landscape. The topology, network rules and SAP settings determine the path that is actually available.
Why this is an operational priority
An SAP server brings together business processes, data and technical identities. Compromise of the Kernel or Message Server does not automatically mean that every business record was accessed; it can nevertheless turn a technical defect into an availability, integrity or confidentiality incident. Assessment must start from versions, exposed interfaces, logs and installation privileges.
CVSS helps prioritize, but it does not replace inventory. Teams must distinguish a theoretically affected version from a service that is actually loaded, reachable and unpatched. That avoids both underestimating the exposure window and announcing a compromise that has not been observed.
What SAP teams should check
Start by inventorying Kernel versions, NetWeaver instances, the Message Server, Web Dispatcher and any EPP components in use. Compare that inventory with the fixed versions in SAP Notes 3747649 and 3759472, then schedule the patches with system owners and business teams.
At the same time, review exposed ports and interfaces, administrative access, recent changes and authentication logs. Look for unexpected registrations, added components, unusual commands and connections from unplanned sources. If an indicator of compromise appears, preserve evidence and activate the incident response process before cleaning the environment.
Technical secrets after an urgent patch
An SAP patch campaign is not limited to replacing binaries. Teams should also know which service accounts, keys and passwords are used by operating systems, interfaces, monitoring tools and vendors. A secret shared across integrations makes revocation broader and investigation less certain.
Assign a distinct secret to each use, tie it to an owner and document its rotation procedure. Do not leave these credentials in an uncontrolled deployment file or shared note. Patching the vulnerability and rotating secrets are separate actions: one reduces the software defect, while the other limits possible persistence from an access already obtained.
The link with Soclyde
Soclyde does not patch SAP Kernel, NetWeaver or enterprise infrastructure, and it cannot determine whether an instance was compromised. Its role is narrower: help a small team generate a unique secret for each technical access, store it in a local-first encrypted vault and quickly retrieve the information needed during a rotation.
This organization reduces secret reuse and makes access review easier after urgent maintenance. It complements SAP patches, segmentation, monitoring and incident response; it does not replace them. To structure your access inventory, read our secure password generator guide or contact Soclyde.
Key takeaways
SAP’s September 8, 2026 Security Patch Day fixes two critical flaws affecting the Kernel and the NetWeaver Message Server. CVE-2026-44756 is rated CVSS 10.0 and CVE-2026-58240 CVSS 9.8; public sources describe both as remotely exploitable without authentication. The priority is to check deployed versions, apply the relevant SAP notes and look for signs of unexpected access.
After patching, inventory technical accounts and rotate secrets that may have been exposed. For a practical next step, read our secure password generator guide or talk to Soclyde.



