# SAP Patches Critical Flaws in NetWeaver, EPP Library

Published: 2026-09-09 · Severity: elevated · Sectors: technology, manufacturing
Canonical: https://vorant.io/reports/a4ad5d1c-070f-5c16-a49e-9e5c6e2ea8cf/sap-patches-critical-flaws-in-netweaver-epp-library

> NCSC-NL advisory details multiple SAP vulnerabilities, including a CVSS 10.0 unauthenticated memory corruption in the EPP processing library and a 9.8 auth-bypass in NetWeaver Message Server.

NCSC-NL published an advisory covering a batch of SAP vulnerabilities patched across numerous products including the SAP Extended Passport Protocol (EPP) processing library, SAP NetWeaver Message Server, @sap/cds-mtxs NPM library, SAP GUI for Java, SAP ABAP Development Tools, SAP Integration Suite, SAP NetWeaver Business Client, SAP Web Dispatcher, Internet Communication Manager, SAP Content Server, SAP S/4HANA Intercompany Matching and Reconciliation, and SAP Manufacturing Integration and Intelligence. The most severe issue, CVE-2026-44756 (CVSS 10.0), is an unauthenticated memory-safety flaw in the EPP processing library triggerable via malformed EPP headers, potentially impacting confidentiality, integrity, and availability. CVE-2026-58240 (CVSS 9.8) allows unauthenticated network attackers to register unauthorized components in the NetWeaver Message Server environment due to missing authentication on internal application server component registration, enabling full system compromise. CVE-2026-76969 (CVSS 9.4) exposes sensitive credentials in multitenant CAP applications, permitting unauthorized tenant data access and manipulation. CVE-2026-66768 (CVSS 9.0) lets a low-privileged attacker execute arbitrary commands in SAP GUI for Java due to improper enforcement of trust level policies.

## Mentioned in this report

- Vulnerabilities: CVE-2026-2332, CVE-2026-44756, CVE-2026-44766, CVE-2026-58240, CVE-2026-58243, CVE-2026-66768, CVE-2026-76958, CVE-2026-76967, CVE-2026-76968, CVE-2026-76969, CVE-2026-76971

Source reporting: https://advisories.ncsc.nl/2026/ncsc-2026-0356.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/a4ad5d1c-070f-5c16-a49e-9e5c6e2ea8cf/sap-patches-critical-flaws-in-netweaver-epp-library.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
