SAP security advisory – September 2026 monthly rollup (AV26-894)

MediumCanadian Centre for Cyber Security · Canadian Centre for Cyber Security·

At a glance

Severity
Medium
Used in attacks
No flaws named
Vendors and products
SAP
Industries
Manufacturing
Reported by
1 outlet

As of September 8, 2026, SAP_SE is affected by vulnerabilities in the following products:

  • SAP Extended Passport (EPP) Processing – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20
  • SAP NetWeaver (Message Server) - versions KERNEL 9.16, 9.18, 9.19, and 9.20
  • SAP Cloud Application Programming Model (CAP)
    • prior or equal to 1.183
    • prior or equal to 2.7.6
    • prior or equal to 3.9.6
    • prior or equal to 4.0.2
  • SAP NetWeaver (SAP GUI for Java) - version BC-FES-JAV 8.10
  • SAP Integration Suite
    • Version Cloud Integration - Trading Partner Management V2 2.9.2,
    • Version B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0
  • SAP NetWeaver Business Client – versions BC-WD-CLT-BUS 8.00 and 8.10
  • SAP NetWeaver Application Server for ABAP and ABAP Platform – versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20

The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available.

Reproduced in full under licence from Canadian Centre for Cyber Security. © Canadian Centre for Cyber Security. Written by Canadian Centre for Cyber Security.

Coverage

One outlet has carried this so far.

  1. Canadian Centre for Cyber SecurityOfficial SourceFirst reported

    2026-09-08 18:03 UTC

Related stories