SAP disclosed CVE-2026-58240 (also tracked as S4GET), a critical missing-authentication and trust-validation flaw in SAP NetWeaver Message Server, rated CVSS 9.8. An unauthenticated attacker able to reach the Message Server’s public SAP GUI-facing port can send a crafted packet, cause an IP address to be trusted across an SAP cluster, and bypass Gateway trust boundaries. The resulting rogue component registration or trusted-peer impersonation can enable interception, alteration, redirection, or disruption of SAP inter-component traffic and may lead to remote code execution as the SAP operating-system account <sid>adm.
Affected deployments include SAP NetWeaver Message Server components on kernel versions 9.16, 9.18, 9.19, and 9.20. SAP issued the definitive remediation in Security Note 3759472; organizations should apply it immediately, identify and restrict Message Server public-port exposure—especially Internet exposure—and review cluster and Gateway trust configurations. No confirmed in-the-wild exploitation or CISA KEV listing had been reported at publication, but the public network attack surface and likelihood of rapid weaponization make this a high-priority patching issue.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
SAP released the definitive fix for the critical CVSS 9.8 SAP NetWeaver Message Server flaw as Security Note 3759472 during its September 2026 Security Patch Day. The issue permits an unauthenticated attacker to abuse Message Server trust registration and potentially obtain code execution as the SAP operating-system account.
Tenable Nessus provides the sap_netweaver_kernel_3759472.nasl plugin to detect SAP NetWeaver Application Server installations affected by CVE-2026-58240. Detection requires an installed-software inventory item and the ParanoidReport setting.
Onapsis Research Labs reported the pre-authentication SAP NetWeaver Message Server vulnerability tracked as CVE-2026-58240 to SAP through a coordinated-disclosure partnership.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
tenable.com
Open sourcethreataft.com
Open sourceonapsis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.