Multiples vulnérabilités dans les produits SAP (08 septembre 2026)
Multiple vulnerabilities have been discovered in SAP products, including remote code execution, privilege escalation, and denial-of-service attacks. These vulnerabilities allow an attacker to potentially execute arbitrary code, elevate privileges, and cause a denial-of-service. The affected products span a wide range of SAP solutions, including ABAP Developer Tools, Commerce Cloud, Extended Passport, Integration Suite, Manufacturing Integration and Intelligence, NetWeaver, S/4HANA, and more. Users are strongly advised to refer to the vendor's security notes for available patches.
Multiple vulnerabilities have been identified within various SAP products, presenting significant security risks. These vulnerabilities could be exploited to achieve remote code execution, elevate privileges, and trigger denial-of-service conditions. The affected products include, but are not limited to, ABAP Developer Tools versions SAP_BASIS 750 through 758 and 816, Commerce Cloud (Search and Navigation) versions COM_CLOUD 2211 and 2211-JDK21, Extended Passport (EPP) Processing versions KRNL64NUC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20, Integration Suite versions Cloud Integration - Trading Partner Management V2 2.9.2 and B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0, Manufacturing Integration and Intelligence versions XMII 15.4 and 15.5, NetWeaver (GUI for Java) version BC-FES-JAV 8.10, NetWeaver (Message Server) versions KERNEL 9.16, 9.18, 9.19 and 9.20, NetWeaver and ABAP Platform versions SAP_BASIS 700, 701, 702, 731, 740, 750, 751, 752, 753, 754, 755, 756, 757 and 758, NetWeaver Application Server for ABAP and ABAP Platform versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20, NetWeaver Business Client versions BC-WD-CLT-BUS 8.00 and 8.10, Process Integration (SOAP Adapter) versions MESSAGING 7.50 and SAP_XIAF 7.50, S/4HANA (Finance for Advanced Payment Management) versions S4CORE 105, 106 and 107, S/4HANA (Finance for Advanced Payment Management) versions UIAPFI70 800, 900, 901 and 902, S/4HANA (Intercompany Matching and Reconciliation) versions SAPSCORE 136, S4CORE 104, 105, 106, 107, 108 and 109, and SAPUI5(Frame Options Allowlist) versions SAP_UI 750, 754, 755, 756, 757, 758, 816 and UI_700 200. The vulnerabilities are associated with CVE identifiers including CVE-2026-2332, CVE-2026-34477, CVE-2026-44756, CVE-2026-44766, CVE-2026-58234, CVE-2026-58240, CVE-2026-58243, CVE-2026-66767, CVE-2026-66768, CVE-2026-76958, CVE-2026-76959, CVE-2026-76960, CVE-2026-76961, CVE-2026-76962, CVE-2026-76963, CVE-2026-76967, CVE-2026-76968, CVE-2026-76969, CVE-2026-76971, and CVE-2026-76977. Users are strongly advised to refer to the vendor's security notes for the latest information and available patches. The bulletin of security SAP september-2026 of 08 september 2026 can be found at https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html.