LmCast :: Stay tuned in

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

Recorded: Sept. 8, 2026, 3:10 p.m.

Original Summarized

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

News

Featured
Latest

Trezor data breach impact now reaches 81,000 customers

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

N-able patches max severity N-central flaw amid ongoing attacks

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

Adobe fixes critical Magento zero-day exploited to backdoor servers

Webinar: The forgotten Google Workspace access that can lead to a breach

Tutorials

Latest
Popular

How to access the Dark Web using the Tor Browser

How to enable Kernel-mode Hardware-enforced Stack Protection in Windows 11

How to use the Windows Registry Editor

How to backup and restore the Windows Registry

How to start Windows in Safe Mode

How to remove a Trojan, Virus, Worm, or other Malware

How to show hidden files in Windows 7

How to see hidden files in Windows

Webinars
Downloads

Latest
Most Downloaded

Qualys BrowserCheck

STOPDecrypter

AuroraDecrypter

FilesLockerDecrypter

AdwCleaner

ComboFix

RKill

Junkware Removal Tool

Deals

Categories

eLearning

IT Certification Courses

Gear + Gadgets

Security

VPNs

Popular

Best VPNs

How to change IP address

Access the dark web safely

Best VPN for YouTube

Forums
More

Virus Removal Guides
Startup Database
Uninstall Database
Glossary
Send us a Tip!
Welcome Guide

HomeNewsSecuritySAP warns of maximum severity 'OVERPASS' kernel vulnerability

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

By Sergiu Gatlan

September 8, 2026
10:55 AM
0

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.
Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library.
Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data.
The flaw can be exploited over SAP Internet Communication Manager (ICM), the networking component of the SAP Application Server that connects the SAP System (SAP NetWeaver Application Server) to the Internet via HTTP, HTTPS, and SMTP.
According to Onapsis' estimates, more than 10,000 Internet-facing SAP systems use the vulnerable component and are potentially exposed to attacks exploiting the CVE-2026-44756 flaw.
"A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative," Onapsis CTO JP Perez-Etchegoyen said on Tuesday.
"It counts only HTTP-reachable systems and materially undercounts the SAP Web Dispatcher, which proxies its backend and returns no distinguishing SAP banner on its root path, making it structurally hard for Internet-wide scanners to attribute."
S4GET, logic flaw in SAP's NetWeaver Message Server
Today, SAP also addressed CVE-2026-58240, a critical missing authentication vulnerability in the SAP NetWeaver Message Server named S4GET by Onapsis Research Labs.
After successful exploitation, unauthenticated attackers can access the entire SAP system cluster and execute malicious payloads and arbitrary commands remotely across the network.
"The flaw is triggered through the same public port that every SAP GUI client connects to, so it cannot be firewalled away without breaking the end-user logon," Onapsis security researcher Pablo Artuso explained.
"Exploitation requires no credentials, no certificate, and no pre-existing misconfiguration. A successful attack yields full remote code execution as <sid>adm, the OS-level user that runs SAP, on every application server in the cluster."
Last month, SAP fixed another maximum-severity vulnerability (CVE-2026-58231) in the Commerce Cloud cloud-based e-commerce platform, which threat intelligence company Defused flagged as actively exploited in attacks days after it was patched.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP security flaws to its list of actively exploited vulnerabilities, including three that were abused by ransomware gangs.
SAP is a German multinational software company that reported total revenues exceeding €36 billion in fiscal year 2025 and provides services to 99 of the 100 largest companies worldwide.

Once attackers have valid credentials, only 37% of their actions are blocked

Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
Get the report

Related Articles:
SAP warns of critical flaws in NetWeaver and Commerce CloudWebinar: The forgotten Google Workspace access that can lead to a breachMassive Microsoft 365 outage causes auth issues, service failuresNearly 22,000 Microsoft Exchange servers vulnerable to hijack attacksMax severity SAP Commerce Cloud flaw now targeted in attacks

Authentication
NetWeaver
OVERPASS
S4GET
SAP

Sergiu Gatlan
Sergiu is a news reporter who has covered the latest cybersecurity and technology developments for over a decade. Email or Twitter DMs for tips.

Previous Article

Post a Comment Community Rules

You need to login in order to post a comment

Not a member yet? Register Now

You may also like:

  Upcoming Webinar

Popular Stories

OpenAI admits it didn't disclose rogue AI wiki hijacking incident

Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

Sponsor Posts

Unify ransomware protection and recovery for every client

CTI Starter Kit + 2026 SANS CTI Survey

See how attackers exploit passkey enrollment, and why hardware-bound biometrics raise enterprise identity assurance.

  Upcoming Webinar

Follow us:

Main Sections

News
Webinars
VPN Buyer Guides
SysAdmin Software Guides
Downloads
Virus Removal Guides
Tutorials
Startup Database
Uninstall Database
Glossary

Community

Forums
Forum Rules
Chat

Useful Resources

Welcome Guide
Sitemap

Company

About BleepingComputer
Contact Us
Send us a Tip!
Advertising
Write for BleepingComputer
Social & Feeds
Changelog

Terms of Use - Privacy Policy - Ethics Statement - Affiliate Disclosure

Copyright @ 2003 - 2026 Bleeping Computer® LLC - All Rights Reserved

Login

Username

Password

Remember Me

Sign in anonymously

Sign in with Twitter

Not a member yet? Register Now


Reporter

Help us understand the problem. What is going on with this comment?

Spam

Abusive or Harmful

Inappropriate content

Strong language

Other

Read our posting guidelinese to learn what content is prohibited.

Submitting...
SUBMIT

SAP has disclosed several critical security vulnerabilities within its products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. This vulnerability, tracked as CVE-2026-44756 and named OVERPASS by Onapsis security researchers, originates from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation allows unprivileged threat actors to execute arbitrary commands on vulnerable SAP hosts with administrative privileges, resulting in a full compromise of the underlying SAP processes and business data. This flaw can be leveraged through the SAP Internet Communication Manager (ICM), which is the networking component connecting the SAP System to the internet via protocols like HTTP, HTTPS, and SMTP. Onapsis estimates that more than 10,000 Internet-facing SAP systems utilize the vulnerable component and are potentially exposed to attacks exploiting CVE-2026-44756. The research notes that while this count is conservative, it specifically focuses on HTTP-reachable systems, underscoring the challenge in attributing exploitation across the entire infrastructure due to components like the SAP Web Dispatcher not providing distinguishing banners on their root paths.

In addition to the kernel flaw, SAP addressed another critical issue, CVE-2026-58240, which involves a missing authentication vulnerability within the SAP NetWeaver Message Server named S4GET, as reported by Onapsis Research Labs. This flaw allows unauthenticated attackers to gain access to the entire SAP system cluster and execute malicious payloads and arbitrary commands remotely across the network. The ease of exploitation is noted because the flaw is triggered through the same public port used by every SAP GUI client connection, meaning it cannot be effectively firewalled without disrupting end-user logon processes. As explained by Onapsis security researcher Pablo Artuso, exploitation requires no credentials, certificate, or pre-existing misconfiguration, and a successful attack grants remote code execution under the context of the OS-level user running SAP, specifically <sid>adm, on every application server in the cluster.

Furthermore, SAP addressed another maximum severity vulnerability, CVE-2026-58231, which affects the Commerce Cloud cloud-based e-commerce platform. This flaw was flagged by the threat intelligence company Defused as actively exploited in attacks shortly after its patching. The context of these disclosures is situated within a broader security landscape where even with valid credentials, defenses often fail; the Blue Report 2026 measures defenses across customer production environments and indicates that once attackers gain initial access using valid credentials, prevention scores drop sharply. SAP, a multinational company providing services to nearly all major global enterprises, has reported substantial revenues and is responsible for maintaining the security posture of these complex systems. The reports contribute to ongoing cybersecurity discussions concerning enterprise identity assurance and system-level defenses.