【Security Vulnerability Alert】SAP has issued a critical security advisory for multiple products

 
2026/9/24 ~ 2027/3/24
View Count:24

Forwarded from Taiwan Computer Emergency Response Team / Coordination Center Security Information Alert TWCERTCC-200-202609-00000019

[Content Description]
SAP released its September regular updates, patching a total of 20 vulnerabilities, of which 4 are high-risk security vulnerabilities (CVE-2026-44756, CVSS:10.0, CVE-2026-58240, CVSS:9.8, CVE-2026-76969, CVSS:9.4 and CVE-2026-66768, CVSS:9.0).
CVE-2026-44756, a memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker can exploit specially crafted network requests, causing undefined behavior and abnormal termination of the program.
CVE-2026-58240, SAP NetWeaver Message Server has insufficient authenticity verification of internal application server components during the registration process. An unauthenticated attacker with network access may perform unauthorized operations in the application environment.
CVE-2026-76969, the @sap/cds-mtxs NPM library does not adequately check certain functions used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker can exploit specially crafted requests to obtain sensitive credentials.
CVE-2026-66768, SAP GUI for Java fails to properly enforce trust-level policies for certain function calls from connected backend systems. A low-privileged attacker can exploit this vulnerability to cause arbitrary commands to be executed on the victim's machine by manipulating the connected backend system.

[Affected Platforms]
SAP Extended Passport (EPP) Processing KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20 versions
SAP NetWeaver (Message Server) KERNEL 9.16, 9.18, 9.19, 9.20 versions
Specific versions of sap/cds-mtxs
SAP NetWeaver (SAP GUI for Java) BC-FES-JAV 8.10 version

[Recommended Measures]
Apply patches according to the solution released on the official website https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html?isu_page=1

[References]
1. https://www.twcert.org.tw/tw/cp-169-11207-b9e4b-1.html

Files
system_update_alt官方網站
system_update_alt參考資料
Top↑