Skip to content

Enterprise software, read for what it costs and who signs for it.

Security

Attackers could get into SAP systems without a password. SAP fixed it yesterday.

SAP published 19 new Security Notes and one update on 8 September.

ERP LEADERS news desk · · First reported by support.sap.com · Edition no. 2
Photo: Saturnalia0/Wikimedia, CC0 · original

Four were rated Critical.

The highest-rated flaw is a memory corruption issue in Extended Passport processing at CVSS 10.0, tracked as CVE-2026-44756. A missing authentication check in the NetWeaver Message Server scored 9.8, tracked as CVE-2026-58240.

Another fix covers credential disclosure in multitenant applications built on the Cloud Application Programming Model at 9.4, tracked as CVE-2026-76969. Improper access control in SAP GUI for Java scored 9.0, tracked as CVE-2026-66768.

SAP rated five more notes High. The highest was an 8.8 privilege escalation in ABAP Developer Tools.

Onapsis, which reviews every Patch Day, wrote, "The new CVSS 10.0 note requires special attention because it can be exploited remotely and without authentication."

Check the Message Server note first. No credentials are needed to reach the flaw, and the Message Server runs on every ABAP system.

Which of your SAP systems will still be unpatched on Friday?

Sources

Spotted an error? Tell us. Every correction is logged on Standards.

Your reading room

Companies in this story

Our file on SAP

  1. 20 SeptFiled later

    SAP's chief executive said voice replaces much data entry in three years.

  2. 19 SeptFiled later

    KPMG cut jobs in its SAP and AI teams. Partners averaged £880,000.

  3. 17 SeptFiled later

    Broadcom raised VMware prices by 10x or more, European cloud providers say.

  4. 17 SeptFiled later

    Grocery Outlet's SAP launch cut gross margin by almost 2 points.

  5. 11 SeptFiled later

    Zeiss dropped the clean rebuild of its SAP after about €200 million.

All 18 SAP stories

Every story here is open to read. The ERP LEADERS brief goes one step further.

One ERP programme per issue, laid out for a steering committee. Issue 01 is the Zeiss case. Read issue 01 or sign up for the brief.

Founding reader

Welcome back. · Issue 01

1 comment under this story on LinkedIn. Read the discussion

Keep reading

The ERP LEADERS brief Get issue 01