SAP: SAP warns of maximum severity 'OVERPASS' kernel vulnerability

SAP: SAP warns of maximum severity 'OVERPASS' kernel vulnerability

SAP Patches Critical Vulnerabilities in September 2026 Security Updates

SAP released its September 2026 security updates, addressing 20 vulnerabilities across multiple products, including two critical flaws with maximum severity ratings.

The most severe, CVE-2026-44756 (OVERPASS), is a memory corruption flaw in the SAP Kernel’s Extended Passport Protocol (EPP) processing library. Exploiting this buffer overflow weakness allows unprivileged attackers to execute arbitrary commands with administrative privileges, leading to full system compromise. The vulnerability affects SAP Internet Communication Manager (ICM), exposing over 10,000 internet-facing SAP systems to potential attacks, according to Onapsis researchers.

Additionally, SAP patched CVE-2026-58240 (S4GET), a missing authentication flaw in the SAP NetWeaver Message Server. This vulnerability enables unauthenticated attackers to remotely execute malicious payloads and commands across an entire SAP system cluster, with no credentials or misconfigurations required. Exploitation occurs via the same port used by SAP GUI clients, making firewall restrictions impractical without disrupting user access.

Last month, SAP also fixed CVE-2026-58231, a critical flaw in Commerce Cloud that was actively exploited shortly after its patch release. Since 2021, CISA has listed 14 SAP vulnerabilities as actively exploited, including three leveraged by ransomware groups.

SAP, a global leader in enterprise software with €36 billion in 2025 revenue, serves 99 of the world’s 100 largest companies, underscoring the high stakes of these security risks.

Source: https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/

SAP TPRM report: https://www.rankiteo.com/company/saps

"id": "sap1788885365",
"linkid": "saps",
"type": "Vulnerability",
"date": "9/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '99 of the world’s 100 largest '
                                              'companies',
                        'industry': 'Technology/Software',
                        'location': 'Global',
                        'name': 'SAP',
                        'size': '€36 billion (2025 revenue)',
                        'type': 'Enterprise Software Provider'}],
 'attack_vector': ['Remote Exploitation', 'Network-Based'],
 'customer_advisories': 'Apply security updates to prevent exploitation.',
 'date_detected': '2026-09',
 'date_publicly_disclosed': '2026-09',
 'date_resolved': '2026-09',
 'description': 'SAP released its September 2026 security updates, addressing '
                '20 vulnerabilities across multiple products, including two '
                'critical flaws with maximum severity ratings. The most '
                'severe, CVE-2026-44756 (OVERPASS), is a memory corruption '
                'flaw in the SAP Kernel’s Extended Passport Protocol (EPP) '
                'processing library, allowing unprivileged attackers to '
                'execute arbitrary commands with administrative privileges. '
                'Additionally, CVE-2026-58240 (S4GET) is a missing '
                'authentication flaw in the SAP NetWeaver Message Server, '
                'enabling unauthenticated attackers to remotely execute '
                'malicious payloads. CVE-2026-58231, a critical flaw in '
                'Commerce Cloud, was actively exploited shortly after its '
                'patch release.',
 'impact': {'brand_reputation_impact': 'High',
            'operational_impact': 'Full system compromise, remote command '
                                  'execution',
            'systems_affected': '10,000+ internet-facing SAP systems'},
 'investigation_status': 'Patched',
 'post_incident_analysis': {'corrective_actions': ['Security patches',
                                                   'Enhanced vulnerability '
                                                   'management'],
                            'root_causes': ['Buffer overflow weakness',
                                            'Missing authentication']},
 'recommendations': 'Apply SAP security patches immediately to mitigate '
                    'critical vulnerabilities.',
 'references': [{'date_accessed': '2026-09', 'source': 'SAP Security Updates'},
                {'date_accessed': '2026-09', 'source': 'Onapsis Research'},
                {'date_accessed': '2026-09', 'source': 'CISA'}],
 'response': {'communication_strategy': 'Public security updates',
              'containment_measures': 'Security patches released',
              'remediation_measures': 'Patching vulnerabilities',
              'third_party_assistance': 'Onapsis researchers'},
 'stakeholder_advisories': 'Critical patching required for SAP customers.',
 'title': 'SAP Patches Critical Vulnerabilities in September 2026 Security '
          'Updates',
 'type': ['Memory Corruption', 'Missing Authentication'],
 'vulnerability_exploited': ['CVE-2026-44756 (OVERPASS)',
                             'CVE-2026-58240 (S4GET)',
                             'CVE-2026-58231']}
Great! Next, complete checkout for full access to Rankiteo Blog.
Welcome back! You've successfully signed in.
You've successfully subscribed to Rankiteo Blog.
Success! Your account is fully activated, you now have access to all content.
Success! Your billing info has been updated.
Your billing was not updated.