SAP’s September 2026 Security Patch Day, released September 8, includes 19 new security notes plus an update to a previously released note, and among them is a maximum-severity flaw: CVE-2026-44756, a memory corruption vulnerability in SAP Extended Passport (EPP) Processing carrying a CVSS score of 10.0. The flaw affects SAP NetWeaver kernel components and Web Dispatcher across versions 7.22 through 9.20, a range that spans the large majority of SAP’s currently supported on-premises deployments. SAP’s own advisory states the company “strongly recommends that the customer visits the support portal and applies patches on priority to protect their SAP landscape.”
A perfect CVSS score on a component this widely deployed is a genuine emergency-patch trigger, not routine monthly maintenance. NetWeaver’s kernel and Web Dispatcher sit at the core of how SAP systems handle inbound requests, which means a memory corruption bug here is close to the front door of an ERP environment that, for most enterprises running it, holds financial records, supply chain data and HR systems in one place. SAP has not indicated active exploitation as of publication, but a 10.0 score on infrastructure this central tends to draw fast reverse-engineering attention from researchers and attackers alike once the patch itself reveals what was broken.
The original insight worth surfacing here is about patch scope rather than the flaw itself: the affected version range, 7.22 through 9.20, is unusually wide for a single CVE, which means organizations running anything from older, long-supported NetWeaver deployments to the newest releases are all in scope. Security teams should not assume a recent SAP environment is automatically safe from a flaw this broad, and should confirm patch applicability against the specific note rather than assuming version recency is protection on its own.
Source: SAP Security Patch Day
Related coverage: Oracle’s Perfect-10 Flaw Lives in Plain Sight and Ordinary Git Access Just Became Root Access.