SAP Patches Critical Kernel Flaw Allowing Remote Code Execution

SAP's September 2026 security update addresses 20 vulnerabilities, including a buffer overflow in the Extended Passport Protocol library tracked as CVE-2026-44756. The flaw, dubbed OVERPASS, lets unprivileged attackers run arbitrary commands with admin privileges on exposed SAP systems via the Internet Communication Manager. Onapsis estimates over 10,000 internet-facing SAP instances are potentially vulnerable, and a separate critical authentication bypass in NetWeaver Message Server was also fixed.
The OVERPASS vulnerability stems from a memory handling error in the Extended Passport Protocol library. It can be triggered remotely through the Internet Communication Manager, granting unprivileged users full administrative control over affected systems. Onapsis identified over ten thousand publicly reachable SAP instances, though the actual number may be higher due to hidden Web Dispatcher proxies.
A separate authentication gap in the NetWeaver Message Server, designated S4GET, allows unauthenticated remote code execution across entire system clusters. This flaw is particularly dangerous because it exploits the standard port used by SAP clients, making it impossible to block with firewalls. Notably, SAP recently patched a Commerce Cloud flaw that was exploited within days, and CISA has tracked 14 SAP vulnerabilities actively abused since 2021.
The widespread deployment of SAP across global enterprises means these vulnerabilities could expose sensitive business data and disrupt critical operations for thousands of organizations. If exploited, attackers may gain deep access to financial systems, supply chains, or government services, potentially leading to significant economic damage and reputational harm. While patching is essential, the difficulty of securing legacy systems suggests that some exposed instances may remain vulnerable for an extended period, increasing the risk of targeted ransomware campaigns.