Updated October 2026.
SAP releases security fixes on the second Tuesday of each month. Its September 2026 Security Patch Day (8 September) was a heavy one, and organisations running SAP should treat it as a priority.
Key facts
- 19 new security notes, plus 1 update to an earlier note
- 4 rated critical
- Highest severity: CVSS 10.0, a memory corruption issue in SAP Extended Passport (EPP) processing
- Other affected products include SAP NetWeaver (Message Server, SAP GUI for Java), SAP Cloud Application Programming Model (CAP), ABAP Developer Tools, SAP Commerce Cloud, several S/4HANA components, and SAPUI5. Scores range from 2.2 to 10.0.
Why SAP patching cannot wait
SAP systems hold finance, HR, supply chain and customer data. Attackers have repeatedly exploited SAP vulnerabilities within days of disclosure. In India, CERT-In’s 2026 guidance expects very fast remediation of known exploited vulnerabilities, as little as 12 hours for internet-facing and crown-jewel systems. ERP systems usually count as crown jewels.
Checklist for SAP Basis and security teams
- Log in to the SAP Support Portal and review all HotNews and High Priority notes for your components and versions.
- Map each note to your landscape: production, quality and development, plus any internet-facing systems such as Fiori, Portal or Commerce.
- Apply critical notes first, after quick regression testing. Where patching is delayed, use the workarounds SAP documents.
- Check for signs of exploitation in security audit logs and gateway and message server logs.
- Keep kernel and SAP GUI versions current. Many issues are fixed only in newer releases.
- Document everything for audits, especially for SOX, RBI or SEBI compliance.
Career note
SAP security, including GRC, Basis hardening and vulnerability management for ERP, is a niche with strong demand in Indian GCCs and consultancies. Learning SAP security tools and certifications can set you apart.
Leave a Reply