SEPTEMBER 14, 2026
Live Feed
Back to database
Case File

CVE-2026-58240

CRITICAL · CVSS 9.8 EPSS 0.34% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-08 · Last synced 2026-09-14

CyberRota Analysis

AI-Generated

The vulnerability in SAP NetWeaver Message Server allows unauthenticated attackers with network access to register unauthorized components due to insufficient validation of internal application server components. This could lead to severe consequences, including unauthorized actions that compromise the confidentiality, integrity, and availability of the system. Organizations using SAP NetWeaver should prioritize addressing this critical vulnerability to safeguard their application environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58240
Severity
CRITICAL
CVSS
9.8
EPSS
0.34%

Original NVD Description

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system.