The Tool Desk
Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →Outbyte PC Repair FREERepair Windows errors before they cause bigger problemsFix Now →SAP’s September 8, 2026 Security Patch Day listed nine new critical- or high-priority vulnerabilities: four critical and five high. The official bulletin identifies each affected product, version range, CVE, SAP Security Note and CVSS score. SAP recommends that customers check the relevant notes and apply patches with priority; whether a particular system is affected depends on its installed components and versions.
What SAP patched on September 8, 2026
SAP reported 19 new security notes for the scheduled patch day. Nine entries were critical or high priority. An update to an August security note appears separately from those nine new entries, so it is not included in the count below. The following list reflects the priorities and CVSS scores in SAP’s bulletin, not an independent severity assessment. SAP Security Patch Day bulletin
| Priority | CVE and SAP Note | Issue | Product | CVSS score listed by SAP |
|---|---|---|---|---|
| Critical | CVE-2026-44756 / 3747649 | Memory corruption | SAP Extended Passport (EPP) Processing | 10.0 |
| Critical | CVE-2026-58240 / 3759472 | Missing authentication check | SAP NetWeaver Message Server | 9.8 |
| Critical | CVE-2026-76969 / 3798315 | Credential disclosure in multitenant CAP applications | SAP Cloud Application Programming Model (CAP) Library, sap/cds-mtxs | 9.4 |
| Critical | CVE-2026-66768 / 3781729 | Improper access control | SAP NetWeaver SAP GUI for Java | 9.0 |
| High | CVE-2026-58243 / 3772411 | Privilege escalation; update to an August 2026 note | SAP ABAP Developer Tools | 8.8 |
| High | CVE-2026-76958 / 3792978 | XML External Entity (XXE) | SAP Integration Suite | 8.5 |
| High | CVE-2026-76967 / 3784138 | Insecure deserialization | SAP NetWeaver Business Client | 7.8 |
| High | CVE-2026-66767 / 3757002 | Memory corruption | SAP NetWeaver Application Server for ABAP and ABAP Platform | 7.7 |
| High | CVE-2026-2332 / 3791068 | CRLF injection due to Jetty components | SAP Commerce Cloud Search and Navigation | 7.4 |
Which products and versions should administrators check?
The bulletin includes affected component and product version ranges, including kernel and SAP_BASIS releases, CAP library ranges, Cloud Integration Trading Partner Management versions, SAP NetWeaver Business Client 8.00 and 8.10, and SAP Commerce Cloud 2211 variants. Those examples are not enough to determine whether a customer’s landscape is exposed: administrators need to match the exact installed component and version against the corresponding SAP Security Note.
Open each applicable note in the SAP Support Portal’s Security Notes and check its affected-version list and correction instructions. Product names alone are not a reliable way to establish exposure.
#1 Best Overall
How to prioritize remediation
- Inventory installed components and versions. Compare the actual landscape—including relevant kernel, SAP_BASIS, library and product versions—with the affected ranges in SAP’s individual notes.
- Use SAP’s priority and the note’s correction guidance. Start with applicable critical and high entries, while also reviewing the prescribed fix and any operational requirements in each note.
- Plan the change for the specific environment. The bulletin recommends priority patching but does not prescribe a customer-specific rollout order or downtime plan. Use your organization’s change controls and the note’s instructions to plan deployment.
- Recheck the note before implementation. The Security Note is the relevant source for the correction and any subsequent changes to its guidance.
SAP’s stated recommendation is: “SAP strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.”
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to count the other September note updates
SAP also reported three updates after the scheduled patch-day announcement: a high-priority update to Note 3485073 and medium-priority updates to Notes 3678417 and 3680888. These are separate from the nine new critical- and high-priority entries. The high-priority update to Note 3772411 is included in the nine-entry list above because SAP identifies it there as a new high-priority entry, while noting that it updates an August issue.
Quick Recap
Best Value
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




