SAP patched a critical flaw in its kernel, tracked as CVE-2026-44756 and dubbed OVERPASS with a top score of 10.0, that lets an unauthenticated, remote attacker run commands with administrative privileges and fully compromise a system. The memory-corruption bug is in the Extended Passport processing library and is reachable over several SAP communication protocols, including through the internet-facing Internet Communication Manager, which researchers say exposes more than 10,000 SAP systems online. In the same update SAP fixed a second 10.0 flaw, a missing-authentication issue in the NetWeaver Message Server that lets attackers run code across an entire SAP cluster without credentials. Both need prompt patching.
Researchers at runZero disclosed seven vulnerabilities in FatFs, a tiny filesystem library that lets devices read FAT and exFAT media like USB drives and SD cards and that is bundled into the firmware of countless embedded and industrial products. The most serious, CVE-2026-6682, is an integer overflow when mounting a FAT32 volume that can lead to memory corruption and code execution, and several bugs are reachable through firmware update flows, not just physical media. The hard part is patching: FatFs is maintained by a single developer who did not respond to the researchers, so most of the memory-corruption flaws have no upstream fix and downstream vendors may never learn they are affected.