# ANSSI Flags Multiple SAP Product Vulnerabilities

Published: 2026-09-08 · Severity: elevated · Sectors: technology, manufacturing, financial-services
Canonical: https://vorant.io/reports/0da96a97-c4f9-54bc-ba5a-42e8357c7efa/anssi-flags-multiple-sap-product-vulnerabilities

> ANSSI advisory details numerous SAP vulnerabilities across NetWeaver, S/4HANA and related products enabling RCE, privilege escalation, and DoS.

France's ANSSI (CERT-FR) issued an advisory summarizing SAP's September 2026 security patch bulletin, covering a broad set of vulnerabilities across many SAP products including ABAP Developer Tools, Commerce Cloud, NetWeaver (multiple components including ABAP Platform, Message Server, GUI for Java, Business Client), S/4HANA (Finance for Advanced Payment Management, Intercompany Matching and Reconciliation), Integration Suite, Manufacturing Integration and Intelligence, Process Integration (SOAP Adapter), SAPUI5, and Web Dispatcher/ICM/Content Server components. Affected version ranges span many SAP_BASIS, KERNEL, and product-specific releases, indicating wide applicability across SAP customer estates running unpatched systems.

The vulnerability classes identified include remote code execution, privilege escalation, remote denial of service, SQL injection, server-side request forgery (SSRF), cross-site request forgery (CSRF), confidentiality breaches, and security policy bypass. No exploitation in the wild is mentioned, and no proof-of-concept or technical exploitation detail is provided in the advisory. ANSSI directs administrators to SAP's official September 2026 security notes bulletin for the specific patches and to apply them according to affected product and version.

Given the number of CVEs and the presence of remote code execution and privilege escalation among the affected components, organizations running SAP NetWeaver, S/4HANA, or related SAP Business Suite products should prioritize patch review and apply the September 2026 SAP Security Notes across all listed products in their estate. This is a routine monthly vendor patch cycle disclosure rather than an active exploitation event.

## Mentioned in this report

- Vulnerabilities: CVE-2026-2332, CVE-2026-34477, CVE-2026-44756, CVE-2026-44766, CVE-2026-58234, CVE-2026-58240, CVE-2026-58243, CVE-2026-66767, CVE-2026-66768, CVE-2026-76958, CVE-2026-76959, CVE-2026-76960, CVE-2026-76961, CVE-2026-76962, CVE-2026-76963, CVE-2026-76967, CVE-2026-76968, CVE-2026-76969, CVE-2026-76971, CVE-2026-76977

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1134

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/0da96a97-c4f9-54bc-ba5a-42e8357c7efa/anssi-flags-multiple-sap-product-vulnerabilities.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
