Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-58240 2026-09-07

CVE-2026-58240: Critical SAP NetWeaver Message Server Authentication Flaw Scores 9.8

"SAP NetWeaver's Message Server fails to properly verify the authenticity of internal application server components during registration, letting an unauthenticated network attacker register a rogue component."

SAP NetWeaver's Message Server fails to properly verify the authenticity of internal application server components during registration, letting an unauthenticated network attacker register a rogue component.

What Is It

CVE-2026-58240 is an improper authentication weakness in the SAP NetWeaver Message Server. The service does not sufficiently validate the authenticity of internal application server components when they register. An unauthenticated attacker with network access to the affected service can exploit this to register an unauthorized component and potentially perform unauthorized actions within the application environment.

SAP assigned it a CVSS 3.1 base score of 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges, and no user interaction required. The CVE was published by SAP SE as the CNA and currently carries NVD status "Received," meaning the record has not yet been through NVD analysis.

Why It Matters

Every barrier that normally slows an attacker is absent here: no credentials, no user to phish, and no unusual conditions to line up. Impact is rated High across all three of confidentiality, integrity, and availability, meaning a successful registration of a rogue component puts the affected system's data and operation at risk simultaneously. The Message Server sits at the center of a NetWeaver landscape's internal communication, so anything that can impersonate a legitimate application server component is well positioned inside the environment.

There is no CISA KEV entry for CVE-2026-58240 as of this writing, so active exploitation is not confirmed at this time.

What's Vulnerable

Per SAP's advisory data, the affected product is SAP NetWeaver (Message Server) from SAP SE, with a default status of unaffected except for the following kernel versions:

No CPE entries were published in the NVD record at the time of writing.

Patch Status

SAP published this as part of its Security Patch Day process, with remediation details in SAP Note 3759472. Administrators should consult that note and apply the corresponding kernel fix for their affected version. SAP's advisory data does not specify a fixed version number, and no mandated remediation deadline applies.

Sources