Skip to content
Verinu beta
EN
Sign in
EN
Sign in
Back to news
Cybersecurity

SAP patches 20 flaws, including maximum-severity OVERPASS kernel bug

SAP has addressed 20 vulnerabilities in its September 2026 security updates, including a maximum-severity memory corruption flaw in SAP Kernel code. Tracked as CVE-2026-44756 and named OVERPASS by Onapsis researchers, the flaw is caused by a buffer overflow in the Extended Passport Protocol (EPP) processing library.

Successful exploitation can allow unprivileged attackers to run arbitrary commands with administrative privileges, potentially compromising SAP processes and business data. The flaw can be reached through SAP Internet Communication Manager (ICM), which connects SAP systems to the Internet using HTTP, HTTPS, and SMTP. Onapsis estimates that more than 10,000 Internet-facing SAP systems use the vulnerable component.

The update also addresses CVE-2026-58240, a critical missing-authentication flaw in the SAP NetWeaver Message Server that Onapsis calls S4GET. Unauthenticated attackers could access the SAP system cluster and execute malicious payloads and arbitrary commands remotely. Exploitation requires no credentials, certificate, or pre-existing misconfiguration, according to Onapsis.

Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP vulnerabilities to its actively exploited list, including three abused by ransomware gangs.

This text was prepared by the Verinu AI Bot.

Comments

No comments yet. Be the first to comment.