Skip to content
SAP Patches Maximum Severity “Overpass” Flaw

SAP Patches Maximum Severity “Overpass” Flaw

Infosecurity-Magazine September 9, 2026

Over 10,000 internet-facing SAP systems might be vulnerable to a maximum severity vulnerability in the SAP kernel, security vendor Onapsis has warned.

The firm’s Onapsis Research Labs (ORL) discovered and responsibly disclosed to SAP the Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing, tracked as CVE-2026-44756.

“The ORL team discovered that boundary validation is missing during the deserialization of EPP data resulting in a memory safety violation when processing externally supplied length fields,” it explained in a blog on September 8.

“This allows an unauthenticated attacker to send crafted network requests containing a malformed EPP header, causing undefined behavior and abnormal program termination.”

Onapsis explained that, because EPP processing is shared kernel code the vulnerability is reachable from the SAP GUI layer every end user connects to, and from the RFC layer that links SAP systems to one another.

It warned that the bug is remotely exploitable without authentication and exists by default in a range of SAP components.

Exploitation could enable remote attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, enabling full compromise of SAP business data and processes.

At the time of writing there was no active exploitation, although this is likely to change.

More CVEs for SAP Customers to Patch

Onapsis also urged SAP customers to patch CVE-2026-58240, another critical bug, this time with a CVSS score of 9.8.

Dubbed “S4GET,” it affects the Message Server in specific versions of SAP S/4HANA and could allow an attacker to gain access to the entire SAP system cluster to remotely execute malicious payloads and arbitrary commands, the firm explained.

Two further vulnerabilities include:

A credential disclosure flaw (CVE-2026-76969) in multitenant applications using SAP Cloud Application Programming Model (CAP). It has a CVSS score of 9.4 and is patched with Security Note #3798315

An improper access control vulnerability (CVE-2026-66768) in SAP NetWeaver with a CVSS score of 9.0. It is patched with SAP Security Note #3781729 , and could enable execution of arbitrary commands on a victim’s machine

Onapsis urged SAP customers to take action immediately, especially to patch CVE-2026-44756.

CISA: Patch Legacy SAP Vulnerabilities Urgently News 7 April 2021

CISA: Patch Legacy SAP Vulnerabilities Urgently

ERP Apps Under Attack Warns US-CERT News 26 July 2018

ERP Apps Under Attack Warns US-CERT

Report: Chinese Breach of USIS Started with SAP News 13 May 2015

Report: Chinese Breach of USIS Started with SAP

New Exploits Target Components of SAP Applications News 2 May 2019

New Exploits Target Components of SAP Applications

March Patch Tuesday Fixes Two Zero Days News 13 March 2019

March Patch Tuesday Fixes Two Zero Days

What’s Hot on Infosecurity Magazine?

Researcher Publishes CrowdStrike Privilege Escalation Zero Day

NCSC Warns Shadow AI Creates New Security Risks

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused

Multiple Class Action Lawsuits Filed Against IDScan

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials

CREST Onboards First Cohort for AI-Enabled Pentesting Accreditation

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

New CREST AI Standards to Deliver AI-Enabled Pentesting Accreditation

Gambling Goblin Turns Brazilian Government Sites Into SEO Weapons

How Industry Coalitions Are Rallying to Secure Open Source Software for the AI Era

NCSC Warns Shadow AI Creates New Security Risks

Understanding Frontier AI Defense: What Cyber and IT Leads Need to Know

Human Risk in Cybersecurity: Protecting Your Organization Beyond Technology

Same Front Door, New Visitors: Securing Humans and AI Agents at the Browser

Behind the Curtain of Microsoft 365 Cybersecurity: Lessons from Overlooked Resilience Gaps

How to Manage Enterprise Cyber Resilience in the Age of AI

Why Resilience‑Focused Cloud Design Is Your Best Defense Against Modern Attacks

How Faster Cyber-Attacks Are Reshaping Enterprise Cybersecurity Strategies

Researchers Claim First Fully Agentic Ransomware: JadePuffer

AI is Already Powering Cyber-Attacks. Can it Power Cyber Defense?

Google Cloud's New CISO Chris Betz on Integrating AI in Cyber Defenses

How World Cup Password Trends Can Increase Active Directory Risk

New CISA Guide Helps Agencies Adopt SASE For Zero Trust