CRITICAL 9.8 NVD
CVE-2026-58240
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated a
SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.
References
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-09-08 via NVD.
Risk Timeline
CVE Disclosed2026-09-08 · 2 days ago
Remediation Resources
Official Advisory
url.sap/sapsecuritypatchdayAnalysis & PoC
me.sap.com/notes/3759472
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.