Our takeSAP's September patch day fixes two critical flaws (CVE-2026-44756, CVSS 10.0) in Kernel and NetWeaver Message Server. Patch immediately if you run these systems — enterprises and smaller shops alike.Cyber Resilience desk
Sources (1)
- cert_eu · cert_eu
What this means for you — Security leader:SAP released patches for two critical vulnerabilities (including CVSS 10.0 CVE-2026-44756 in the Kernel/NetWeaver Message Server). Review your SAP estate, test, and apply the September 2026 Security Notes immediately.
What this means for you — Lean IT orgs:If you run any SAP products, check whether your vendor or MSP has applied the September 2026 patches. Ask them today — these are critical and already public.
What this means for you — MSP:Audit all clients running SAP Kernel or NetWeaver Message Server. Deploy the September 2026 Security Notes (including the CVSS 10.0 OVERPASS fix) and confirm completion across every affected stack.
What this means for you — Researcher:SAP's September 2026 Patch Day includes CVE-2026-44756 (CVSS 10.0 memory corruption in Extended Passport processing, OVERPASS) and a second critical flaw in the Kernel and NetWeaver Message Server.