Back Infosecurity-Magazine SAP Patches Maximum Severity “Overpass” Flaw
Over 10,000 internet-facing SAP systems might be vulnerable to a maximum severity vulnerability in the SAP kernel, security vendor Onapsis has warned.
The firm’s Onapsis Research Labs (ORL) discovered and responsibly disclosed to SAP the Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing, tracked as CVE-2026-44756.
“The ORL team discovered that boundary validation is missing during the deserialization of EPP data resulting in a memory safety violation when processing externally supplied length fields,” it explained in a blog on September 8.
“This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination.”
Onapsis explained that, because EPP processing is shared kernel code the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another.
It warned that the bug is remotely exploitable without authentication and exists by default in a range of SAP components.
Exploitation could enable remote attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, enabling full compromise of SAP business data and processes.
At the time of writing there was no active exploitation, although this is likely to change.
More CVEs for SAP Customers to Patch
Onapsis also urged SAP customers to patch CVE-2026-58240, another critical bug, this time with a CVSS score of 9.8.
Dubbed “S4GET,” it affects the Message Server in specific versions of SAP S/4HANA and could allow an attacker to gain access to the entire SAP system cluster to remotely execute malicious payloads and arbitrary commands, the firm explained.
Two further vulnerabilities include:
A credential disclosure flaw (CVE-2026-76969) in multitenant applications using SAP Cloud Application Programming Model (CAP). It has a CVSS score of 9.4 and is patched with Security Note #3798315
An improper access control vulnerability (CVE-2026-66768) in SAP NetWeaver with a CVSS score of 9.0. It is patched with SAP Security Note #3781729 , and could enable execution of arbitrary commands on a victim’s machine
Onapsis urged SAP customers to take action immediately, especially to patch CVE-2026-44756.
CISA: Patch Legacy SAP Vulnerabilities Urgently News 7 April 2021
CISA: Patch Legacy SAP Vulnerabilities Urgently
ERP Apps Under Attack Warns US-CERT News 26 July 2018
ERP Apps Under Attack Warns US-CERT
Report: Chinese Breach of USIS Started with SAP News 13 May 2015
Report: Chinese Breach of USIS Started with SAP
New Exploits Target Components of SAP Applications News 2 May 2019
New Exploits Target Components of SAP Applications
March Patch Tuesday Fixes Two Zero Days News 13 March 2019
March Patch Tuesday Fixes Two Zero Days
What’s Hot on Infosecurity Magazine?
Researcher Publishes CrowdStrike Privilege Escalation Zero Day
NCSC Warns Shadow AI Creates New Security Risks
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
Multiple Class Action Lawsuits Filed Against IDScan
BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation
North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation
Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons
How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era
NCSC Warns Shadow AI Creates New Security Risks
Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know
Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology
Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser
Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps
How to Manage Enterprise Cyber Resilience in the Age of AI
Why Resilience‑Focused Cloud Design Is Your Best Defense Against Modern Attacks
How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies
Researchers Claim First Fully Agentic Ransomware: JadePuffer
AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?
Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses
How World Cup Password Trends Can Increase Active Directory Risk
New CISA Guide Helps Agencies Adopt SASE For Zero Trust
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
