SAP releases 19 new security notes in its September patch cycle
SAP said it issued 19 new security notes and updated one earlier note on 8 September; its list included two critical flaws scored 10.0 and 9.8 on CVSS.
Event / data period: 2026-09-08
Published: · Updated:
SAP said its 8 September 2026 security patch day released 19 new security notes addressing vulnerabilities in its products and updated one previously issued note. The company urged customers to apply the patches as a priority.
SAP listed a memory-corruption flaw in Extended Passport processing, CVE-2026-44756, with a CVSS score of 10.0, and a missing authentication check in the NetWeaver Message Server, CVE-2026-58240, scored 9.8. The bulletin also covered notes of high and medium priority for other products; these are the ratings published by SAP.
Data
Security development
Security event or institutional action reported by the source.
- · Occurred
SAP released 19 new notes on its September security patch day
SAP said it released 19 new security notes and updated one earlier note; two critical vulnerabilities were listed with CVSS scores of 10.0 and 9.8.
Methodology
The event date and description summarise the action reported by the source; no additional measurement or forecast is made.
Updated:
Measure reported by the source
Key quantitative figure stated by the source.
- New security notes released
- 19 count
- 2026-09-08 · Observed
Methodology
Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.
Updated:
Subjects and places
Subject proposals
- Crime, law and justiceSuggested
- Preserved editorial category/topic; broad candidate onlysupport.sap.com ↗