Critical OVERPASS Vulnerability in SAP Kernel Exposed

Critical OVERPASS Vulnerability in SAP Kernel Exposed

First seen 8 Sep 2026, 16:43 UTC CybersecuritynewsBleepingcomputersupport.sap.comonapsis.comnvd.nist.gov 73.5

Article Content

Browse articles
ThreatCluster

On September 8, 2026, SAP released critical security updates addressing 20 vulnerabilities, including CVE-2026-44756, a severe memory corruption flaw in the Extended Passport (EPP) processing. This vulnerability, named OVERPASS, allows remote attackers to execute arbitrary commands on SAP systems without authentication, potentially compromising sensitive business data. The flaw is accessible through various SAP components, affecting over 10,000 Internet-facing SAP systems. SAP has urged all customers to apply the patches immediately to mitigate risks. As of the publication date, there is no evidence of active exploitation in the wild, but the vulnerability's critical nature necessitates prompt action. The patching process is considered an emergency priority for affected organizations. The vulnerability was disclosed by Onapsis Research Labs, highlighting the importance of timely updates in the SAP ecosystem.

Key Points: • CVE-2026-44756 (OVERPASS) allows remote command execution on vulnerable SAP systems. • SAP recommends immediate patching for over 10,000 exposed systems worldwide. • No active exploitation has been observed as of the latest reports.

Ask AI about this cluster

Timeline

2020-07-14
CVE-2020-6287 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2025-04-24
CVE-2025-31324 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-10
CVE-2026-34477 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-04-14
CVE-2026-2332 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
CVE-2026-58231 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
CVE-2026-58243 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-08
SAP releases September 2026 security updates
SAP issued 20 security notes, including a critical patch for CVE-2026-44756 affecting EPP processing.
support.sap.com
2026-09-08
CVE-2026-44756 disclosed
Onapsis Research Labs reported the OVERPASS vulnerability, allowing remote command execution without authentication.
onapsis.com
2026-09-08
Onapsis estimates 10,000 vulnerable systems
Onapsis identified over 10,000 Internet-facing SAP systems potentially exposed to the OVERPASS vulnerability.
bleepingcomputer
2026-09-08
CVE-2026-76958 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE