On September 8, 2026, SAP released Security Notes as part of its September Security Patch Day. These notes address two critical vulnerabilities affecting a broad range of SAP products. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing. Onapsis Research Labs (ORL) nicknamed this flaw "OVERPASS" after discovering and responsibly disclosing it.
On September 8, 2026, SAP released Security Notes as part of its September Security Patch Day. These notes address two critical vulnerabilities affecting a broad range of SAP products. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing.
Onapsis Research Labs (ORL) nicknamed this flaw "OVERPASS" after discovering and responsibly disclosing it. The second vulnerability, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server.
Both vulnerabilities are remotely exploitable without requiring authentication. Researchers report that successful exploitation of either flaw can lead to arbitrary operating system command execution. This occurs under the account owning the SAP installation, potentially compromising the system and its business data.
CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.
