# SAP releases 19 new security notes in its September patch cycle

> SAP said it issued 19 new security notes and updated one earlier note on 8 September; its list included two critical flaws scored 10.0 and 9.8 on CVSS.

- Canonical URL: https://newsverum.com/en/news/sap-september-2026-security-patch-day-19-notes
- Publisher: Newsverum
- Section: Security
- Published: 2026-10-06T08:59:01+00:00
- Updated: 2026-10-07T05:58:39+03:00
- Event / data period: 2026-09-08
- Other editions: [Türkçe](https://newsverum.com/tr/news/sap-september-2026-security-patch-day-19-notes.md), [العربية](https://newsverum.com/ar/news/sap-september-2026-security-patch-day-19-notes.md), [Français](https://newsverum.com/fr/news/sap-september-2026-security-patch-day-19-notes.md), [Español](https://newsverum.com/es/news/sap-september-2026-security-patch-day-19-notes.md), [Deutsch](https://newsverum.com/de/news/sap-september-2026-security-patch-day-19-notes.md), [Português](https://newsverum.com/pt/news/sap-september-2026-security-patch-day-19-notes.md)

SAP said its 8 September 2026 security patch day released 19 new security notes addressing vulnerabilities in its products and updated one previously issued note. The company urged customers to apply the patches as a priority.

SAP listed a memory-corruption flaw in Extended Passport processing, CVE-2026-44756, with a CVSS score of 10.0, and a missing authentication check in the NetWeaver Message Server, CVE-2026-58240, scored 9.8. The bulletin also covered notes of high and medium priority for other products; these are the ratings published by SAP.

## Data

### Security development

Security event or institutional action reported by the source.

Methodology: The event date and description summarise the action reported by the source; no additional measurement or forecast is made.

| date | label | description | status |
|---|---|---|---|
| 2026-09-08 | SAP released 19 new notes on its September security patch day | SAP said it released 19 new security notes and updated one earlier note; two critical vulnerabilities were listed with CVSS scores of 10.0 and 9.8. | occurred |

Sources: <https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html> · Download data: [JSON](https://newsverum.com/api/v1/articles/sap-september-2026-security-patch-day-19-notes/data/security-event?lang=en&format=json) · [CSV](https://newsverum.com/api/v1/articles/sap-september-2026-security-patch-day-19-notes/data/security-event?lang=en&format=csv)

### Measure reported by the source

Key quantitative figure stated by the source.

Methodology: Value is reproduced as stated by the source; a qualifier marks an approximate or bounded figure.

| label | value | unit | period | basis | value_qualifier |
|---|---|---|---|---|---|
| New security notes released | 19 | count | 2026-09-08 | observed | exact |

Sources: <https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html> · Download data: [JSON](https://newsverum.com/api/v1/articles/sap-september-2026-security-patch-day-19-notes/data/security-figures?lang=en&format=json) · [CSV](https://newsverum.com/api/v1/articles/sap-september-2026-security-patch-day-19-notes/data/security-figures?lang=en&format=csv)

## Sources

- [SAP](<https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html>) (Source checked: 2026-10-06; Published: 2026-09-08)

## Correction history

- 2026-10-07T00:55:55+03:00: German and Portuguese editions and translations of the data and correction explanations have been added to this article.
- 2026-10-07T05:58:39+03:00: Data classification added: each figure now carries a measure identifier with its unit, geography, frequency and type. No figure, unit or date changed.

---

Cite the canonical URL above. [Editorial standards and corrections](https://newsverum.com/en/editorial)
