Find notable cyber news and cases, enriched with sources, timelines, and signals.

SAP security patch release for CVE-2026-44756

Security Patch Release
First reported
Last updated
Happening score
H score 45
1 unique sources, 1 articles

Summary

Hide ▲

SAP released security updates for multiple critical vulnerabilities, including CVE-2026-44756, a CVSS 10.0 flaw in SAP Extended Passport (EPP) Processing that can enable unauthenticated remote code execution. The bundle also addresses CVE-2026-58240, CVE-2026-76969, and CVE-2026-66768 across SAP NetWeaver and SAP CAP products. The flaws expose SAP hosts and business data to compromise, credential theft, and unauthorized code execution. SAP operators were urged to patch internet-facing systems first and move quickly because the issues are rated critical.

Related Happenings

SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 patch release

Security Patch Release
H score44 First: 12.08.2026 10:31 Last: 12.08.2026 10:31 Sources 1

About this happening: SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 is a maximum-severity CVSS 10.0 vulnerability that can let an unauthenticated attacker abuse a default authent...

SAP security patch release for CVE-2026-44747

Security Patch Release
H score40 First: 14.07.2026 21:17 Last: 14.07.2026 21:17 Sources 1

About this happening: SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...

SAP July 2026 security updates

Security Patch Release
H score31 First: 14.07.2026 14:42 Last: 14.07.2026 14:42 Sources 1

About this happening: SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...

SAP July 2026 security patch day

Security Patch Release
H score40 First: 14.07.2026 14:17 Last: 14.07.2026 14:17 Sources 1

About this happening: SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...

Oracle E-Business Suite May 2026 Critical Security Patch Update (CVE-2026-46817)

Security Patch Release
H score53 First: 29.06.2026 16:46 Last: 29.06.2026 16:46 Sources 1

About this happening: Oracle's May 2026 Critical Security Patch Update addressed CVE-2026-46817 in Oracle E-Business Suite, a critical flaw in Oracle Payments that could let an...

Latest development: 16.07.2026 13:56

CISA ordered U.S. federal agencies to secure Oracle E-Business Suite systems by Saturday, July 18, after confirming ongoing attacks against CVE-2026-46817 in Oracle Payments. Defused said it observed exploitation on Oracle E-Business honeypots over the weekend, and Oracle had already released the May 2026 Critical Security Patch Update for the flaw.

Timeline

  1. 09.09.2026 09:25 2 articles · 5h ago

    SAP releases security updates for CVE-2026-44756 and three other critical flaws

    Initial Disclosure

    SAP releases security updates for CVE-2026-44756 in SAP Extended Passport (EPP) Processing and three other critical flaws, including CVE-2026-58240, CVE-2026-76969, and CVE-2026-66768. CVE-2026-44756 is a CVSS 10.0 memory-corruption issue in SAP kernel EPP processing that can be exploited remotely without authentication to run operating system commands on SAP hosts with SAP administrative privileges, while the other flaws include a missing authentication check in SAP NetWeaver Message Server, a credential disclosure issue in SAP Cloud Application Programming Model (CAP), and an improper access control bug in SAP NetWeaver SAP GUI for Java. SAP and Onapsis said users should inventory SAP systems, patch internet-facing systems before internal instances, reduce exposure where possible, and monitor for exploitation attempts.

    Show sources