Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7
Tag: sap-kernel (1 article)Clear

Critical SAP kernel flaw lets unauthenticated attackers run commands as admin

SAP patched a critical flaw in its kernel, tracked as CVE-2026-44756 and dubbed OVERPASS with a top score of 10.0, that lets an unauthenticated, remote attacker run commands with administrative privileges and fully compromise a system. The memory-corruption bug is in the Extended Passport processing library and is reachable over several SAP communication protocols, including through the internet-facing Internet Communication Manager, which researchers say exposes more than 10,000 SAP systems online. In the same update SAP fixed a second 10.0 flaw, a missing-authentication issue in the NetWeaver Message Server that lets attackers run code across an entire SAP cluster without credentials. Both need prompt patching.

Check
Apply SAP's September security notes for the kernel and NetWeaver Message Server immediately, and identify any SAP systems whose Internet Communication Manager is reachable from the internet as top priority.
Affected
Organizations running affected SAP systems, especially with an internet-facing Internet Communication Manager (CVE-2026-44756, CVE-2026-58240); unauthenticated remote attackers can execute commands as admin or run code across the whole SAP cluster.
Fix
Patch the SAP kernel and Message Server now, restrict and monitor internet exposure of the Internet Communication Manager and message server ports, and watch for unusual command execution on affected SAP hosts.