SAP Extended Passport (EPP) Processing remote unauthenticated memory corruption flaw (CVE-2026-44756)
Vulnerability
Summary
Hide ▲
Show ▼
SAP has patched CVE-2026-44756, a CVSS 10.0 memory-corruption flaw in SAP Extended Passport (EPP) Processing that can allow remote unauthenticated OS command execution on SAP hosts. The flaw can expose SAP business data and processes to total compromise, and exploitation can reach systems through shared kernel code used by multiple protocols. Onapsis said the issue is named OVERPASS and had not been exploited to date.
Timeline
-
09.09.2026 09:25 2 articles · 5h ago
SAP releases fixes for CVE-2026-44756 and three other critical SAP flaws
Initial DisclosureSAP released security updates for CVE-2026-44756 in SAP Extended Passport (EPP) Processing and three other critical vulnerabilities, including CVE-2026-58240 in SAP NetWeaver Message Server, CVE-2026-76969 in SAP Cloud Application Programming Model (CAP), and CVE-2026-66768 in SAP NetWeaver SAP GUI for Java. CVE-2026-44756 is a CVSS 10.0 memory-corruption flaw in SAP kernel EPP processing that is remotely exploitable without authentication and can allow arbitrary operating system command execution on affected SAP hosts with SAP administrative privileges. Onapsis assigned the name OVERPASS to CVE-2026-44756 and recommended that organizations inventory SAP systems, patch internet-facing systems first, reduce exposure where possible, and monitor for exploitation attempts.
Show sources
- SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution — thehackernews.com — 09.09.2026 09:25
- SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution — thehackernews.com — 09.09.2026 09:25