CyberzSOC

Publication detail
← Back to advisories & guidance

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server ↗ source

September 9, 2026 CERT-EU Advisory

Summary

Critical Vulnerabilities in SAP Kernel On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products [1][3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed “OVERPASS” by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it [2][3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed “S4GET”, is a missing authentication check in the SAP NetWeaver Message Server [3][6]. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds [2][6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as CVE-2026-44756 - “OVERPASS” (CVSS 10.0) CVE-2026-44756 is a memory corruption vulnerability in the SAP Kernel library that processes the Extended Passport (EPP), addressed by SAP Security Note 3747649 [1][4].

News Coverage

DateSourceArticle
2026-09-09 The Hacker News SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution CVE-2026-44756

Articles from the monitored vendor research blogs and security news feeds that reference a CVE cited in this publication, or name the campaign it covers. Coverage begins when feed monitoring started; earlier articles are not indexed.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2026-44756 10.0 Critical SAP_SE SAP Extended Passport (EPP) Processing A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attack…
CVE-2026-58240 9.8 Critical SAP_SE SAP NetWeaver (Message Server) SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauth…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

No KEV-catalogued vendors are named in this publication.