← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 8, 2026 · 11:19via Cyber Security News

SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport

Brief

SAP has released its September 2026 Security Patch Day updates , delivering 19 new security notes and one update to a previously issued note.

The patches address vulnerabilities across SAP NetWeaver, SAP Extended Passport Processing, SAP Cloud Application Programming Model, SAP S/4HANA, SAP Integration Suite, SAP Commerce Cloud, and other enterprise products.

The most severe issue is CVE-2026-44756, a critical memory corruption vulnerability in SAP Extended Passport Processing, tracked under SAP Note 3747649. It carries a CVSS score of 10. 0, the highest possible severity rating.

The flaw affects multiple SAP kernel and Web Dispatcher versions, including KERNEL 7. 22, 7. 53, 7. 54, 7. 77, 7. 89, 7. 93, 8. 04, and 9. 16 through 9.

  • An unauthenticated remote attacker could potentially exploit the memory corruption flaw to compromise confidentiality, integrity, and availability.
Read more on Cyber Security News