SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability
SAP’s September 2026 security updates fix 20 vulnerabilities, including CVE-2026-44756 (OVERPASS), a maximum-severity SAP Kernel memory corruption flaw that can let attackers run commands with administrative privileges and fully compromise SAP hosts. SAP also patched CVE-2026-58240 (S4GET) in the NetWeaver Message Server, a missing-authentication flaw that can expose entire SAP clusters to remote code execution. #CVE-2026-44756 #OVERPASS #CVE-2026-58240 #S4GET #SAPKernel #SAPNetWeaver #SAPICM

Keypoints

  • SAP fixed 20 vulnerabilities across multiple products in its September 2026 updates.
  • CVE-2026-44756 is a critical buffer overflow in the SAP Kernel EPP library.
  • OVERPASS can allow unauthenticated command execution with administrative privileges.
  • More than 10,000 Internet-facing SAP systems may be exposed through SAP ICM.
  • CVE-2026-58240, also known as S4GET, enables full cluster compromise in NetWeaver Message Server.

Read More: https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability/