Bleepingcomputer
Critical OVERPASS Vulnerability in SAP Kernel Exposed
Article Content
On September 8, 2026, SAP released critical security updates addressing 20 vulnerabilities, including CVE-2026-44756, a severe memory corruption flaw in the Extended Passport (EPP) processing. This vulnerability, named OVERPASS, allows remote attackers to execute arbitrary commands on SAP systems without authentication, potentially compromising sensitive business data. The flaw is accessible through various SAP components, affecting over 10,000 Internet-facing SAP systems. SAP has urged all customers to apply the patches immediately to mitigate risks. As of the publication date, there is no evidence of active exploitation in the wild, but the vulnerability's critical nature necessitates prompt action. The patching process is considered an emergency priority for affected organizations. The vulnerability was disclosed by Onapsis Research Labs, highlighting the importance of timely updates in the SAP ecosystem.
Key Points: • CVE-2026-44756 (OVERPASS) allows remote command execution on vulnerable SAP systems. • SAP recommends immediate patching for over 10,000 exposed systems worldwide. • No active exploitation has been observed as of the latest reports.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.