DIRAS TAKE
Urgent: this is a network-accessible, unauthenticated flaw with a high-severity impact (CVSS 9.8), so restrict exposure of Message Server interfaces immediately and prioritize vendor fixes when available.
What is CVE-2026-58240?
An unauthenticated attacker with network access can register unauthorized internal components on SAP NetWeaver (Message Server), allowing them to perform actions that may compromise confidentiality, integrity, and availability. This issue is tracked as CVE-2026-58240. Affected releases include KERNEL 9.16 and 9.x releases 9.18, 9.19, and 9.20. Exploitation requires only network access to the vulnerable Message Server; no credentials or user interaction are required for an attacker to attempt registration of a rogue component.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of SAP SAP NetWeaver (Message Server) are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| SAP NetWeaver (Message Server) | KERNEL 9.16 | |
| 9.x | 9.18 | |
| 9.x | 9.19 | |
| 9.x | 9.20 |
Is CVE-2026-58240 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-58240
- Isolate Message Server endpoints from untrusted networks and limit access to trusted management networks.
- Apply network controls (firewalls, ACLs) to block unnecessary inbound access to Message Server ports.
- Enable and review logging for component registration and suspicious internal component activity.
- Follow SAP security guidance and apply vendor patches or mitigations as soon as they are released.
Frequently asked questions
Is CVE-2026-58240 being actively exploited?
There are no public reports of exploitation of CVE-2026-58240 as of 2026-09-29.
Which SAP NetWeaver (Message Server) versions are affected by CVE-2026-58240?
SAP NetWeaver (Message Server) KERNEL 9.16 and 9.x releases 9.18, 9.19, and 9.20 are listed as affected.
Is there a patch for CVE-2026-58240?
No vendor-fixed versions are listed; a patch is not available based on the provided facts.
Does CVE-2026-58240 require authentication?
No; the vulnerability can be exploited without authentication if an attacker has network access to the Message Server.
References
- nvd.nist.gov/vuln/detail/CVE-2026-58240
- cve.org/CVERecord?id=CVE-2026-58240
- me.sap.com/notes/3759472
- url.sap/sapsecuritypatchday
- All SAP CVEs on CVE Radar
- CVEs published in September 2026