ZeroHour
Story · 3 sources · 3 articlesfirst updated ()

SAP September 2026 Patch Day Fixes CVSS 10.0 Unauthenticated RCE Flaws OVERPASS and S4GET

What's new: First merged summary for this story; all reports agree on the core facts. Establishes the baseline: SAP's September 2026 Patch Day fixes four critical flaws (CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768), including CVSS 10.0 OVERPASS, with no known exploitation and urgent patching advised.
Merged summary · glm-5.3 · rewritten as coverage arrives

SAP patched two critical unauthenticated remote vulnerabilities found by Onapsis — OVERPASS (CVE-2026-44756, CVSS 10.0) in the SAP Kernel and S4GET (CVE-2026-58240, CVSS 9.8) in the NetWeaver Message Server — both enabling OS command execution; over 10,000…

As part of its September 2026 Security Patch Day, SAP released Security Notes 3747649 and 3759472 fixing two critical unauthenticated vulnerabilities discovered by Onapsis. CVE-2026-44756 ('OVERPASS', CVSS 10.0) is a memory corruption flaw caused by missing boundary validation during deserialization of Extended Passport (EPP) data in the SAP Kernel; it is reachable from the web, SAP GUI and RFC layers, cannot be fully mitigated by network or authorization controls, and allows attackers to run arbitrary OS commands with SAP administrative privileges. CVE-2026-58240 ('S4GET', CVSS 9.8) is a missing authentication check in the NetWeaver/S/4HANA Message Server that lets unauthenticated attackers register themselves as trusted cluster nodes — via the same public port used by SAP GUI clients — yielding full RCE as <sid>adm. SAP also patched CVE-2026-76969 (9.4), credential disclosure in SAP Cloud Application Programming Model multi-tenant apps, and CVE-2026-66768 (9.0), improper access control in SAP NetWeaver SAP GUI for Java. Onapsis warns that over 10,000 internet-facing SAP systems may be exposed and recommends prioritizing their patching. No in-the-wild exploitation has been observed to date; CERT-EU urges immediate patching.

  • CVE-2026-44756 ('OVERPASS', CVSS 10.0): unauthenticated kernel memory corruption via missing boundary validation in Extended Passport (EPP) deserialization, leading to OS command execution with SAP administrative privileges
  • OVERPASS is reachable from the web, SAP GUI and RFC layers; no network or authorization control fully mitigates it
  • CVE-2026-58240 ('S4GET', CVSS 9.8): missing authentication check in the NetWeaver/S/4HANA Message Server allowing unauthenticated attackers to register as trusted cluster nodes and achieve RCE as <sid>adm
  • S4GET is reachable through the same public port used by SAP GUI clients, limiting firewall-based mitigation
  • Also patched: CVE-2026-76969 (CVSS 9.4, credential disclosure in SAP Cloud Application Programming Model multi-tenant apps) and CVE-2026-66768 (CVSS 9.0, improper access control in SAP NetWeaver SAP GUI for Java)
  • Fixes delivered via SAP Security Notes 3747649 and 3759472 during SAP's September 2026 Security Patch Day
  • Onapsis, which discovered the flaws, estimates over 10,000 internet-facing SAP systems may be exposed
  • No exploitation in the wild observed to date; Onapsis and CERT-EU recommend immediate patching, prioritizing internet-facing systems

Coverage timeline

  1. · 6d ago
    CERT-EU Advisories· 75
    2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

    SAP patched two critical flaws, OVERPASS (CVE-2026-44756, CVSS 10.0) and S4GET (CVE-2026-58240), allowing unauthenticated attackers to execute OS commands on SAP hosts.

  2. · 6d ago
    The Hacker News· 68
    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP patched CVE-2026-44756 (CVSS 10.0), an unauthenticated kernel memory corruption allowing OS command execution, plus three other critical flaws.

  3. · 6d ago
    Infosecurity Magazine· 82
    SAP Patches Maximum Severity “Overpass” Flaw

    Onapsis warns over 10,000 internet-facing SAP systems may be exposed to maximum-severity unauthenticated RCE flaw CVE-2026-44756 in SAP Extended Passport.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-44756
Unauthenticated buffer overflow in SAP Kernel Extended Passport (EPP) processing

CVE-2026-44756 is a critical (CVSS 10.0) memory-safety flaw — a classic buffer overflow (CWE-120) — in the Extended Passport Protocol (EPP) processing library of SAP Kernel, the core runtime underlying SAP NetWeaver components (SAP's advisories tie the issue to SAP Kernel and the NetWeaver Message Server). An unauthenticated remote attacker can trigger it by sending a crafted network request containing a malformed EPP header to a system that processes EPP traffic. The malformed header causes undefined behavior and abnormal program termination, and SAP's maximum-severity rating plus vendor coverage of the flaw indicate it can enable unauthenticated remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the affected SAP Kernel/NetWeaver components — essentially typical ABAP-stack SAP deployments — is exposed until patched. No public proof-of-concept is known, the flaw is not in CISA KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile), and fixes shipped in SAP's September 2026 Security Patch Day.

Do: Apply the SAP Kernel and NetWeaver Message Server fixes released in SAP's September 2026 Security Patch Day (per the 2026-011 advisory covering this flaw), since specific fixed version numbers are not listed in the available data. As interim mitigation, restrict network access to SAP kernel and message-server services to trusted internal networks and identify any SAP instances exposed to the internet. Check SAP's advisory for the exact patch levels applicable to your kernel releases and prioritize externally reachable systems.

10.0<1%
  • SAP Kernel (Extended Passport Protocol (EPP) processing library)
  • SAP NetWeaver (kernel components, including Message Server, per SAP's 2026-011 advisory)
mass≈100,000+ SAP systems plausibly affected (EPP/kernel ships with virtually all ABAP-stack NetWeaver deployments; public scans have historically shown tens of…
CVE-2026-58240
Unauthenticated Component Registration Flaw in SAP NetWeaver Message Server

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components when they register with the service (CWE-308). An unauthenticated attacker with network access to the affected service can send a crafted registration request to add or impersonate an application server component. Once registered, the attacker can potentially perform unauthorized actions within the SAP application environment, resulting in a high impact on confidentiality, integrity, and availability — reflected in the critical CVSS 9.8 score. Any organization running SAP NetWeaver deployments that rely on the Message Server is affected; the source data does not specify exact affected version ranges. There is no evidence of active exploitation, no public proof-of-concept, and the issue is not in CISA KEV, with EPSS assigning only a ~0.3% 30-day exploitation probability; a fix shipped in SAP's September 2026 Security Patch Day (a release that also patched other critical flaws, including the separately reported 'OVERPASS' SAP Kernel issue).

Do: Apply the SAP NetWeaver Message Server fix from the September 2026 SAP Security Patch Day (referenced as advisory 2026-011) as a priority, since the flaw is unauthenticated and network-triggerable; check SAP's portal for the corrected builds applicable to your release, as no specific version numbers were provided in the source data. Until patching, restrict network access to the Message Server (typically TCP 36xx, e.g., 3600) to trusted application server hosts and internal networks, and verify no message server listener is reachable from the internet. Monitor SAP security notes for updates, as no public exploit exists today.

9.8<1%
  • SAP NetWeaver Message Server
largetens of thousands of SAP NetWeaver installations plausibly affected (Message Server is a standard component of every NetWeaver stack, with a smaller subset…
CVE-2026-66768
Trust Level Policy Bypass Enables RCE in SAP GUI for Java

SAP GUI for Java (CWE-807) fails to correctly enforce its trust level policy when certain functions are invoked from a connected backend system, meaning the client relies on untrusted backend input when making security decisions. To exploit it, an attacker needs low-privileged access to a connected backend (for example, a compromised or malicious SAP backend) and must manipulate that backend to trigger the affected functionality, which also requires interaction from the logged-in user (CVSS UI:R). Successful exploitation yields arbitrary command execution on the victim's workstation, with the changed-scope vector (S:C) allowing a backend-level foothold to break out onto the end-user machine and seriously impacting its confidentiality, integrity, and availability. Anyone running SAP GUI for Java to connect to SAP backends is exposed, particularly in scenarios where less-trusted or low-privileged users can influence the backend their colleagues connect to. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no in-the-wild exploitation is currently known; a fix shipped as part of SAP's September 2026 security patch day.

Do: Deploy the SAP GUI for Java patch released with SAP's September 2026 security updates, checking the SAP advisory for the exact affected and fixed versions for your release line. Inventory endpoints running SAP GUI for Java (especially macOS/Linux desktops) and the backends they connect to, prioritizing users who connect to backends accessible to low-privileged or external users. As an interim mitigation, restrict low-privileged accounts' ability to invoke the affected backend functions and treat backend compromise as a path to client workstation takeover when assessing risk.

9.0<1%
  • SAP GUI for Java
large≈ hundreds of thousands of end users/desktops (subset of SAP's multi-million-user ERP client base using the Java edition)
CVE-2026-76969
Unauthenticated Credential Theft and Tenant Data Tampering in SAP @sap/cds-mtxs

CVE-2026-76969 is a critical flaw (CVSS 9.4) in SAP's @sap/cds-mtxs npm package, the multitenancy component of the SAP Cloud Application Programming Model (CAP), which performs insufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker who can reach the affected endpoints can send specially crafted requests that cause the service to disclose sensitive credentials. With those credentials, the attacker can replace or delete tenant data, resulting in high impact to integrity and availability and partial impact to the confidentiality of business data. Only deployments running multitenant CAP applications on @sap/cds-mtxs with extensibility enabled are affected. Exploitation has not been observed: there is no known public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.

Do: Update the @sap/cds-mtxs dependency in all multitenant CAP applications to the fixed version given in SAP's security advisory for CVE-2026-76969 (part of SAP's September 2026 patch batch) and redeploy the affected applications. Audit whether your CAP applications use multitenancy with extensibility enabled and whether the mtxs endpoints are reachable without authentication, and rotate any tenant-scoped credentials that could have been exposed. As an interim mitigation, restrict network access to the mtxs/sidecar endpoints to trusted callers.

9.4<1%
  • SAP @sap/cds-mtxs npm library (CAP multitenancy service; exploitable when used in multitenant CAP applications with extensib
nichelikely low thousands to low tens of thousands of multitenant CAP tenant deployments (estimate; exact counts unknown)