Critical vulnerabilities in SAP Kernel (OVERPASS) and S/4HANA (S4GET) patched in collaboration with the Onapsis Research Labs
On Wednesday, September 9th at 10:00am EDT, SAP and the Onapsis Research Labs will host a joint threat briefing webinar to these vulnerabilities and the other critical vulnerabilities patched as part of the September 2026 SAP Patch Tuesday release. Register here
Highlights of September SAP Security Notes analysis include:
September Summary – Twenty-two new and updated SAP security patches released, including five HotNews Notes and six High Priority Notes
Critical SAP Kernel vulnerability – Multiple critical aspects of the vulnerability require immediate patching
Onapsis Research Labs Contribution – Our team supported SAP in patching eight vulnerabilities covered by six SAP Security Notes, including three tagged as HotNews
SAP has published twenty-two new and updated SAP Security Notes in its September Patch Day, including five HotNews Notes and six High Priority Notes. Six of the twenty new Security Notes were published in contribution with the Onapsis Research Labs.
The HotNews Notes in Detail
The Onapsis Research Labs (ORL) supported SAP in patching several critical vulnerabilities. SAP Security Note #3747649 ,
Is exploitable remotely and without authentication
Exists by default in a wide range of SAP technology components
Allows remote attackers to run arbitrary operating system commands on the SAP host with SAP administrative privileges, resulting in full compromise of the underlying SAP business data and processes;
It is reachable through several SAP components and several communication protocols, none of them requiring credentials, so no single network control can fully mitigate risk.
More information on the OVERPASS vulnerability can be found here .
SAP Security Note #3771065 ,
Details the S4GET vulnerability and the involved risks can be found here .
A Credential Disclosure vulnerability in multitenant applications using SAP Cloud Application Programming Model (CAP), is patched with SAP Security Note #3798315 ,
The third HotNews Notes that is published in collaboration with the ORL team on SAP’s September Patch Day is SAP Security Note #3781729 ,
The High Priority Notes in Detail
SAP Security Note #3772411 ,
SAP Security Note #3792978 ,
SAP Security Note #3784138 ,
SAP Security Note #3757002 ,
SAP Security Note #3485073 ,
SAP Security Note #3791068 ,
In addition to the three HotNews Notes, the Onapsis Research Labs (ORL) supported SAP in patching three Medium Priority vulnerabilities, all
SAP Security Note #3756450 patches an SQL Injection vulnerability in SAP S/4HANA (Intercompany Matching and Reconciliation). The team was able to access sensitive information by injecting malicious input into certain functions, which was processed by the database without proper validation. The patch improves the sanitization of user input by filtering disallowed keywords.
SAP Security Note #3786489 addresses a Server-Side Request Forgery vulnerability in SAP Manufacturing Integration and Intelligence (SAP MII). The vulnerability enables an attacker to cause the server to initiate arbitrary outbound requests. The processing of these requests could be combined with XML/XSL processing to enable execution of scripts. The note does not provide automatic correction instructions but provides a list of nine manual activities that should be processed to harden the application. SAP Security Note #3750721 patches an Information Disclosure vulnerability in SAP Web Dispatcher, Internet Communication Manager and SAP Content Server. When authenticated as a low-privileged user, the ORL team was able to access certain administrative functionality and obtain sensitive information the system state, resulting in information disclosure. This disclosed information could potentially be used in subsequent attacks.
Summary & Conclusions
With twenty-two SAP Security Notes, SAP’s September Patch Day looks like an average one. But the four new HotNews Notes and six High Priority Notes convert it into a special one. Especially the new CVSS 10.0 note requires special attention because it can be exploited remotely and without authentication.
As always, the Onapsis Research Labs is already updating The Onapsis Platform to incorporate the newly published vulnerabilities into the product so that our customers can protect their businesses.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
