# SAP Security Patch Day September 2026 - note analysis | SNOK

> September 2026: 20 items from SAP on 8 September 2026, four critical, a CVSS 10.0 flaw in the kernel and Web Dispatcher. Who owns each fix and what NIS2…

- Source: https://snok.ai/en/offer/sap-security/sap-security-patch-day/

---

# SAP Security Patch Day - handling the monthly security notes

SAP publishes security notes on a monthly cycle, on the second Tuesday of the month. For teams running SAP this means a recurring decision: which notes apply to our environment, which must be applied immediately, and which can wait for the next service window.

We take that work over - from analysing the notes, through assessing the impact on a specific SAP landscape, to rolling out patches and running regression tests.

Latest edition · 8 September 2026

## [SAP Security Patch Day September 2026 - four critical notes, four different owners](https://snok.ai/en/news/blog/sap-patch-day-september-2026/)

20 items instead of August's 31, so the list looks quiet. It is not. The four critical notes sit in four separate layers - the kernel, inter-instance communication, an npm package and the end user's desktop - and none of them lands where ERP patching normally looks.

The next SAP Security Patch Day after this edition: 13 October 2026 (second Tuesday of the month).

## What your organisation gains

### A decision, not a list of notes

A raw list of SAP notes does not answer the question of what to do in a specific environment. We filter notes against the components, versions and configurations actually in use, and deliver the result as a prioritised list of actions rather than a bulletin to interpret yourself.

### Less time between publication and rollout

The period between a note being published and a patch being applied is a window in which the vulnerability is publicly known and remains open. A standing monthly process shortens that window, because the analysis does not start from scratch each time.

### Evidence of due diligence for audit

Regular, documented handling of security notes is one of the things auditors ask about in the context of NIS2, DORA and the Polish KSC. Each cycle leaves a record: what was analysed, what was applied, and on what basis the remaining items were deferred.

### Without loading the SAP team every month

The monthly note review is repetitive work that competes for time with development projects. Handing it to an external team removes a standing, recurring obligation from the in-house team.

## What we deliver on this project

### Note analysis in the month of publication

After each Patch Day we review the published notes, verifying CVSS ratings, vulnerability descriptions and exploitation conditions. We identify the items relevant to components actually present in the client environment.

### Impact assessment for the client landscape

We map notes to specific systems, versions, enhancement packages and configurations. The result is a list of items that apply to the given environment, separated from those that do not.

### Prioritisation and rollout plan

We split notes into those requiring immediate action, those for the next service window, and those handled on the planned cycle. Priority is based on the CVSS rating, system exposure and business process criticality.

### Patch rollout and regression testing

We apply notes in non-production environments, verify the effects, and then carry out the production rollout in an agreed window. Regression testing scope is set according to process criticality.

### Custom ABAP code scanning

Some notes concern vulnerabilities whose equivalents may also exist in custom code. We scan custom ABAP using the SAP Code Vulnerability Analyzer to catch analogous patterns outside the standard.

### Monthly report for the team and for audit

From each cycle we prepare a record: notes analysed, decisions taken, patches applied, and items deferred together with the rationale. The document can support an internal, external or regulatory audit.

## How we deliver projects in this area

The cycle begins on the day the notes are published, that is the second Tuesday of the month. We review the published security notes and make an initial separation between items relevant to the supported environments and those that do not apply.

We then carry out the impact assessment. Notes are mapped to the client's specific systems, versions and configurations, and for critical items we verify the conditions under which the vulnerability can be exploited.

On this basis we prepare a rollout plan split into immediate actions, items for the next service window, and handling on the planned cycle.

Patches are applied first in non-production environments, then in production during an agreed window, with regression testing scope matched to process criticality.

The cycle closes with a report: what was analysed, what was applied, what was deferred and on what basis. We comment on the same Patch Day publicly in our "Security Tuesday with SNOK" series.

Technology stack

Partnerships backed by our team's certifications. Full authorisation for delivery and support.

## FAQ - SAP Security Patch Day

When is SAP Security Patch Day?+

SAP publishes security notes on the second Tuesday of each month. Outside that cycle, SAP may publish a note off schedule if a vulnerability is critical and requires an immediate response.

Does every note have to be applied straight away?+

No. Some notes concern components a given organisation does not use, so they require no action at all. Among the rest, priority depends on the CVSS rating, system exposure, the conditions for exploiting the vulnerability, and business process criticality. That is why the first step is assessing the impact on the specific environment rather than applying the entire list.

How does Patch Day relate to NIS2, DORA and KSC?+

The regulations do not name SAP Security Patch Day explicitly, but they do require vulnerability management and evidence that the organisation handles it in a structured way. A documented, repeatable process for handling security notes is practical evidence of such management. We cover this in more depth as part of the NIS2, DORA and KSC compliance audit.

Does Patch Day handling cover custom code?+

Yes. SAP notes concern the standard, but similar vulnerability patterns - missing authorisation checks, SQL injection or path traversal, for example - often appear in custom ABAP code as well. The cycle therefore includes scanning custom code, among other things using the SAP Code Vulnerability Analyzer.

Can we commission the analysis only, without the rollout?+

Yes. Some organisations commission only the analysis and prioritisation, and carry out the rollout with their own SAP Basis team. The reverse model is also possible, as is full handling of the cycle on our side.

## Patch Day analysis archive

We comment on every SAP Security Patch Day in our "Security Tuesday with SNOK" series. Below is the full archive of analyses, newest first.

- [SAP Security Patch Day September 2026 - four critical notes, four different owners8 September 2026](https://snok.ai/en/news/blog/sap-patch-day-september-2026/)
- [SAP Patch Day August 2026 - 31 notes and the one question IT never asks11 August 2026](https://snok.ai/en/news/blog/sap-patch-day-august-2026/)
- [SAP Security Patch Day - July 202614 July 2026](https://snok.ai/en/news/blog/sap-security-patch-day-july-2026/)
- [Safe Tuesday: SAP Patch Day June 2026 - two critical notes at the heart of ABAP9 June 2026](https://snok.ai/en/news/blog/sap-patch-day-june-2026/)
- [Safe Tuesday: SAP Patch Day vs NIS2. CVE 10.0, 72 Hours and EUR 10 Million in Fines19 May 2026](https://snok.ai/en/news/blog/sap-patch-day-nis2-cve-72h/)
- [Safe Tuesday with SNOK: May's flood of SAP vulnerabilities12 May 2026](https://snok.ai/en/news/blog/sap-patch-day-may-2026-cvss-96/)
- [SAP Security Patch Day - March 202610 March 2026](https://snok.ai/en/news/blog/sap-security-patch-day-march-2026/)
- [SAP Security Patch Day - February 202610 February 2026](https://snok.ai/en/news/blog/sap-security-patch-day-february-2026/)
- [SAP Security Patch Day – January 202613 January 2026](https://snok.ai/en/news/blog/sap-security-patch-day-january-2026/)
- [🔒 SAP Security Patch Day – December 2025: A comprehensive review of all vulnerabilities9 December 2025](https://snok.ai/en/news/blog/sap-security-patch-day-december-2025/)
- [SAP Security Patch Day – November 202511 November 2025](https://snok.ai/en/news/blog/sap-security-patch-day-november-2025/)
- [Safe Tuesday with SNOK: SAP Security Patch Day – October 202514 October 2025](https://snok.ai/en/news/blog/sap-security-patch-day-october-2025/)
- [Safe Tuesday with SNOK: SAP Security Patch Day June 2025 – Analysis of 14 New Security Notes10 June 2025](https://snok.ai/en/news/blog/sap-security-patch-day-june-2025/)
- [Safe Tuesday with SNOK – SAP Security Patch Day (April 2025)8 April 2025](https://snok.ai/en/news/blog/sap-security-patch-day-april-2025/)
- [Safe Tuesday with SNOK: SAP Patch Day October 20248 October 2024](https://snok.ai/en/news/blog/sap-patch-day-october-2024/)
- [Safe Tuesday with SNOK: SAP Security Patch Day – September 202410 September 2024](https://snok.ai/en/news/blog/sap-security-patch-day-september-2024/)
- [Safe Tuesday with SNOK: Key Updates from the August SAP Security Patch Day13 August 2024](https://snok.ai/en/news/blog/august-sap-security-patch-day-updates/)
- [Safe Tuesday with SNOK: Key updates from the July SAP Security Patch Day9 July 2024](https://snok.ai/en/news/blog/july-sap-security-patch-day-updates/)
- [Safe Tuesday with SNOK: Key updates from the June SAP Patch Day11 June 2024](https://snok.ai/en/news/blog/june-sap-patch-day-key-updates/)
- [Safe Tuesday with SNOK: Key Updates from the May SAP Patch Day15 May 2024](https://snok.ai/en/news/blog/may-sap-patch-day-key-updates/)
- [Safe Tuesday with SNOK: Key updates from the April SAP Security Patch Day9 April 2024](https://snok.ai/en/news/blog/april-sap-security-patch-day-updates/)
- [Safe Tuesday with SNOK: Key Updates from the March SAP Patch Day12 March 2024](https://snok.ai/en/news/blog/march-sap-patch-day-key-updates/)
- [Safe Tuesday with SNOK - Key updates from the February SAP Patch Day13 February 2024](https://snok.ai/en/news/blog/february-sap-patch-day-updates/)
- [SAP Security Patch Day May 2023 – The latest SAP security updates11 May 2023](https://snok.ai/en/news/blog/sap-security-patch-day-may-2023/)
