ZeroHour
Story · 1 source · 1 articlefirst updated ()1

SAP Patches CVSS 10.0 Kernel Flaw 'OVERPASS' Enabling Unauthenticated Remote Code Execution

What's new: First merged summary of this story: SAP's September 2026 patch day addresses four critical flaws, headlined by CVSS 10.0 OVERPASS kernel flaw (CVE-2026-44756) disclosed on 2026-09-09 by The Hacker News and Infosecurity Magazine; Onapsis reports no exploitation to date and over 10,000 potentially exposed internet-facing SAP systems.
Merged summary · glm-5.3 · rewritten as coverage arrives

SAP's September 2026 security updates fix CVE-2026-44756 (OVERPASS, CVSS 10.0), an unauthenticated memory corruption flaw in Extended Passport (EPP) kernel code that allows arbitrary OS command execution with SAP admin privileges; Onapsis warns over 10,000…

SAP's September 2026 security updates patch four critical vulnerabilities discovered by Onapsis Research Labs. The most severe is CVE-2026-44756, dubbed OVERPASS (CVSS 10.0), a missing boundary validation during deserialization of Extended Passport (EPP) data in shared SAP kernel code, causing memory corruption. It is remotely exploitable without authentication by default and could let attackers run arbitrary OS commands with SAP administrative privileges. The Hacker News reports the flaw is reachable from the web, SAP GUI, and RFC layers and states no network or authorization control fully mitigates it; Infosecurity Magazine describes reachability via SAP GUI and RFC. Onapsis warns that over 10,000 internet-facing SAP systems may be exposed and recommends prioritizing their patching. Also patched: CVE-2026-58240 (S4GET, CVSS 9.8), a missing authentication check in the SAP Message Server yielding full RCE as <sid>adm (described as NetWeaver Message Server by The Hacker News and S/4HANA Message Server by Infosecurity Magazine); CVE-2026-76969 (CVSS 9.4), credential disclosure in SAP Cloud Application Programming Model (CAP) multi-tenant apps; and CVE-2026-66768 (CVSS 9.0), improper access control in SAP NetWeaver SAP GUI for Java. Onapsis says none of the flaws have been exploited to date.

  • CVE-2026-44756 (OVERPASS, CVSS 10.0): unauthenticated RCE via missing boundary validation during deserialization of Extended Passport (EPP) data in the SAP kernel, enabling arbitrary OS commands with SAP administrative privileges
  • Flaw resides in shared SAP kernel EPP code; The Hacker News reports reachability from web, SAP GUI, and RFC layers and that no network or authorization control fully mitigates it; Infosecurity Magazine cites SAP GUI and RFC layers
  • Onapsis Research Labs discovered the flaws and warns over 10,000 internet-facing SAP systems may be exposed, urging immediate patching of internet-facing systems
  • CVE-2026-58240 (S4GET, CVSS 9.8): missing authentication check in the SAP Message Server allowing full RCE as <sid>adm; sources describe the affected component as NetWeaver Message Server (The Hacker News) and S/4HANA Message Server…
  • CVE-2026-76969 (CVSS 9.4): credential disclosure in SAP Cloud Application Programming Model (CAP) multi-tenant applications
  • CVE-2026-66768 (CVSS 9.0): improper access control in SAP NetWeaver SAP GUI for Java
  • No active exploitation of any of the four flaws has been observed as of publication on 2026-09-09

Coverage timeline

  1. · 7d ago
    The Hacker News· 68
    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP patched CVE-2026-44756 (CVSS 10.0), an unauthenticated kernel memory corruption allowing OS command execution, plus three other critical flaws.

Vulnerabilities in this storyAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-44756
Unauthenticated buffer overflow in SAP Kernel Extended Passport (EPP) processing

CVE-2026-44756 is a critical (CVSS 10.0) memory-safety flaw — a classic buffer overflow (CWE-120) — in the Extended Passport Protocol (EPP) processing library of SAP Kernel, the core runtime underlying SAP NetWeaver components (SAP's advisories tie the issue to SAP Kernel and the NetWeaver Message Server). An unauthenticated remote attacker can trigger it by sending a crafted network request containing a malformed EPP header to a system that processes EPP traffic. The malformed header causes undefined behavior and abnormal program termination, and SAP's maximum-severity rating plus vendor coverage of the flaw indicate it can enable unauthenticated remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the affected SAP Kernel/NetWeaver components — essentially typical ABAP-stack SAP deployments — is exposed until patched. No public proof-of-concept is known, the flaw is not in CISA KEV, EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile), and fixes shipped in SAP's September 2026 Security Patch Day.

Do: Apply the SAP Kernel and NetWeaver Message Server fixes released in SAP's September 2026 Security Patch Day (per the 2026-011 advisory covering this flaw), since specific fixed version numbers are not listed in the available data. As interim mitigation, restrict network access to SAP kernel and message-server services to trusted internal networks and identify any SAP instances exposed to the internet. Check SAP's advisory for the exact patch levels applicable to your kernel releases and prioritize externally reachable systems.

10.0<1%
  • SAP Kernel (Extended Passport Protocol (EPP) processing library)
  • SAP NetWeaver (kernel components, including Message Server, per SAP's 2026-011 advisory)
mass≈100,000+ SAP systems plausibly affected (EPP/kernel ships with virtually all ABAP-stack NetWeaver deployments; public scans have historically shown tens of…
CVE-2026-58240
Unauthenticated Component Registration Flaw in SAP NetWeaver Message Server

SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components when they register with the service (CWE-308). An unauthenticated attacker with network access to the affected service can send a crafted registration request to add or impersonate an application server component. Once registered, the attacker can potentially perform unauthorized actions within the SAP application environment, resulting in a high impact on confidentiality, integrity, and availability — reflected in the critical CVSS 9.8 score. Any organization running SAP NetWeaver deployments that rely on the Message Server is affected; the source data does not specify exact affected version ranges. There is no evidence of active exploitation, no public proof-of-concept, and the issue is not in CISA KEV, with EPSS assigning only a ~0.3% 30-day exploitation probability; a fix shipped in SAP's September 2026 Security Patch Day (a release that also patched other critical flaws, including the separately reported 'OVERPASS' SAP Kernel issue).

Do: Apply the SAP NetWeaver Message Server fix from the September 2026 SAP Security Patch Day (referenced as advisory 2026-011) as a priority, since the flaw is unauthenticated and network-triggerable; check SAP's portal for the corrected builds applicable to your release, as no specific version numbers were provided in the source data. Until patching, restrict network access to the Message Server (typically TCP 36xx, e.g., 3600) to trusted application server hosts and internal networks, and verify no message server listener is reachable from the internet. Monitor SAP security notes for updates, as no public exploit exists today.

9.8<1%
  • SAP NetWeaver Message Server
largetens of thousands of SAP NetWeaver installations plausibly affected (Message Server is a standard component of every NetWeaver stack, with a smaller subset…
CVE-2026-66768
Trust Level Policy Bypass Enables RCE in SAP GUI for Java

SAP GUI for Java (CWE-807) fails to correctly enforce its trust level policy when certain functions are invoked from a connected backend system, meaning the client relies on untrusted backend input when making security decisions. To exploit it, an attacker needs low-privileged access to a connected backend (for example, a compromised or malicious SAP backend) and must manipulate that backend to trigger the affected functionality, which also requires interaction from the logged-in user (CVSS UI:R). Successful exploitation yields arbitrary command execution on the victim's workstation, with the changed-scope vector (S:C) allowing a backend-level foothold to break out onto the end-user machine and seriously impacting its confidentiality, integrity, and availability. Anyone running SAP GUI for Java to connect to SAP backends is exposed, particularly in scenarios where less-trusted or low-privileged users can influence the backend their colleagues connect to. There is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days, so no in-the-wild exploitation is currently known; a fix shipped as part of SAP's September 2026 security patch day.

Do: Deploy the SAP GUI for Java patch released with SAP's September 2026 security updates, checking the SAP advisory for the exact affected and fixed versions for your release line. Inventory endpoints running SAP GUI for Java (especially macOS/Linux desktops) and the backends they connect to, prioritizing users who connect to backends accessible to low-privileged or external users. As an interim mitigation, restrict low-privileged accounts' ability to invoke the affected backend functions and treat backend compromise as a path to client workstation takeover when assessing risk.

9.0<1%
  • SAP GUI for Java
large≈ hundreds of thousands of end users/desktops (subset of SAP's multi-million-user ERP client base using the Java edition)
CVE-2026-76969
Unauthenticated Credential Theft and Tenant Data Tampering in SAP @sap/cds-mtxs

CVE-2026-76969 is a critical flaw (CVSS 9.4) in SAP's @sap/cds-mtxs npm package, the multitenancy component of the SAP Cloud Application Programming Model (CAP), which performs insufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker who can reach the affected endpoints can send specially crafted requests that cause the service to disclose sensitive credentials. With those credentials, the attacker can replace or delete tenant data, resulting in high impact to integrity and availability and partial impact to the confidentiality of business data. Only deployments running multitenant CAP applications on @sap/cds-mtxs with extensibility enabled are affected. Exploitation has not been observed: there is no known public proof of concept, the issue is not in CISA KEV, and EPSS estimates only a ~0.3% probability of exploitation within 30 days.

Do: Update the @sap/cds-mtxs dependency in all multitenant CAP applications to the fixed version given in SAP's security advisory for CVE-2026-76969 (part of SAP's September 2026 patch batch) and redeploy the affected applications. Audit whether your CAP applications use multitenancy with extensibility enabled and whether the mtxs endpoints are reachable without authentication, and rotate any tenant-scoped credentials that could have been exposed. As an interim mitigation, restrict network access to the mtxs/sidecar endpoints to trusted callers.

9.4<1%
  • SAP @sap/cds-mtxs npm library (CAP multitenancy service; exploitable when used in multitenant CAP applications with extensib
nichelikely low thousands to low tens of thousands of multitenant CAP tenant deployments (estimate; exact counts unknown)