Skip to content
feed: live
>_0dayNews
sap

SAP September Patches: CVSS 10 RCE in EPP Processing

SAP's September 2026 Security Patch Day includes a CVSS 10.0 unauthenticated RCE in Extended Passport Processing and multiple additional critical updates.

SAP September Patches: CVSS 10 RCE in EPP Processing
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
kilobaudDave "Kilobaud" Ferris·Published ·2 min read

SAP’s September 2026 Security Patch Day included a CVSS 10.0 vulnerability in SAP Extended Passport (EPP) Processing. The flaw allows unauthenticated attackers to execute arbitrary code, with the advisory noting severe impact across confidentiality, integrity, and availability. A perfect CVSS score on an unauthenticated RCE in an enterprise authentication framework is a straightforward apply-immediately situation.

EPP is SAP’s enterprise single sign-on and authentication token infrastructure. Flaws in authentication processing layers carry broader blast radius than product-level bugs: if you can exploit the thing that hands out credentials, you are not limited to one application. SAP has not publicly confirmed in-the-wild exploitation of this specific flaw as of September 2026, but that is information from the moment of disclosure and not a forecast for the next thirty days.

The full security note, affected versions, and patch packages are available through SAP’s Security Patch Day resources and the SAP ONE Support Launchpad for subscribers. If your organization runs SAP EPP or relies on SAP’s single sign-on infrastructure, this is the note to treat as critical regardless of its labeled severity tier in your vendor’s ticketing system.

The September patch context

SAP ships security notes monthly on Patch Tuesday, the same Tuesday cadence Microsoft uses. This September batch included fixes across multiple SAP products beyond EPP. The EPP flaw is the highest-severity item in the batch at CVSS 10.0, but the others should follow in your normal security-note remediation queue.

This is the second time in 2026 that SAP has shipped a CVSS 10.0 vulnerability in an enterprise product. In August, SAP Commerce Cloud’s CVE-2026-58231 hit a perfect CVSS score in its RCE path, and attackers began exploiting it within days of the patch landing. That one moved from “patch released” to “active exploitation underway” in under 96 hours. The SAP-targeting threat landscape has become faster, not slower, at weaponizing disclosed vulnerabilities once a fix gives researchers something to reverse.

What to do

Apply SAP’s September security notes on your standard critical patch cycle, prioritizing the EPP Processing fix. Verify the patch is applied on all instances, including development and staging environments that may run older builds. SAP’s July patch day write-up covered the process for tracking and applying security notes for teams newer to SAP’s patching cadence.

If you cannot patch immediately, review network access controls for SAP EPP interfaces. The vulnerability is unauthenticated, which means any system that can reach the EPP endpoint on the network can potentially trigger it. Network segmentation does not fix the vulnerability but reduces exposure while the patch is queued.

Found this useful? Share it.