Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: memory-corruption (2 articles)Clear

Critical SAP kernel flaw lets unauthenticated attackers run commands as admin

SAP patched a critical flaw in its kernel, tracked as CVE-2026-44756 and dubbed OVERPASS with a top score of 10.0, that lets an unauthenticated, remote attacker run commands with administrative privileges and fully compromise a system. The memory-corruption bug is in the Extended Passport processing library and is reachable over several SAP communication protocols, including through the internet-facing Internet Communication Manager, which researchers say exposes more than 10,000 SAP systems online. In the same update SAP fixed a second 10.0 flaw, a missing-authentication issue in the NetWeaver Message Server that lets attackers run code across an entire SAP cluster without credentials. Both need prompt patching.

Check
Apply SAP's September security notes for the kernel and NetWeaver Message Server immediately, and identify any SAP systems whose Internet Communication Manager is reachable from the internet as top priority.
Affected
Organizations running affected SAP systems, especially with an internet-facing Internet Communication Manager (CVE-2026-44756, CVE-2026-58240); unauthenticated remote attackers can execute commands as admin or run code across the whole SAP cluster.
Fix
Patch the SAP kernel and Message Server now, restrict and monitor internet exposure of the Internet Communication Manager and message server ports, and watch for unusual command execution on affected SAP hosts.

Seven flaws in the FatFs library expose millions of embedded devices, mostly unpatched

Researchers at runZero disclosed seven vulnerabilities in FatFs, a tiny filesystem library that lets devices read FAT and exFAT media like USB drives and SD cards and that is bundled into the firmware of countless embedded and industrial products. The most serious, CVE-2026-6682, is an integer overflow when mounting a FAT32 volume that can lead to memory corruption and code execution, and several bugs are reachable through firmware update flows, not just physical media. The hard part is patching: FatFs is maintained by a single developer who did not respond to the researchers, so most of the memory-corruption flaws have no upstream fix and downstream vendors may never learn they are affected.

Check
Inventory devices and firmware that bundle the FatFs library, especially anything that mounts USB, SD-card, or externally supplied filesystem images or accepts firmware updates, and ask vendors whether their products include FatFs.
Affected
Embedded, industrial, and consumer devices that bundle FatFs to read FAT or exFAT media (CVE-2026-6682 and six others); malicious media or update images can crash devices or corrupt memory toward code execution.
Fix
Where possible, restrict which USB, SD-card, and update-image sources a device will mount, isolate affected devices, and press vendors for firmware updates, since most of these flaws have no upstream fix.