MobbleOpen in Mobble ⇢
Technology · Cybersecurity · published 2026-09-08 · via BleepingComputer

SAP Patches Critical Kernel Flaw Allowing Remote Code Execution

Image via BleepingComputer
Image via BleepingComputer

SAP's September 2026 security update addresses 20 vulnerabilities, including a buffer overflow in the Extended Passport Protocol library tracked as CVE-2026-44756. The flaw, dubbed OVERPASS, lets unprivileged attackers run arbitrary commands with admin privileges on exposed SAP systems via the Internet Communication Manager. Onapsis estimates over 10,000 internet-facing SAP instances are potentially vulnerable, and a separate critical authentication bypass in NetWeaver Message Server was also fixed.

Expanded Detail

The OVERPASS vulnerability stems from a memory handling error in the Extended Passport Protocol library. It can be triggered remotely through the Internet Communication Manager, granting unprivileged users full administrative control over affected systems. Onapsis identified over ten thousand publicly reachable SAP instances, though the actual number may be higher due to hidden Web Dispatcher proxies.

A separate authentication gap in the NetWeaver Message Server, designated S4GET, allows unauthenticated remote code execution across entire system clusters. This flaw is particularly dangerous because it exploits the standard port used by SAP clients, making it impossible to block with firewalls. Notably, SAP recently patched a Commerce Cloud flaw that was exploited within days, and CISA has tracked 14 SAP vulnerabilities actively abused since 2021.

Context

The widespread deployment of SAP across global enterprises means these vulnerabilities could expose sensitive business data and disrupt critical operations for thousands of organizations. If exploited, attackers may gain deep access to financial systems, supply chains, or government services, potentially leading to significant economic damage and reputational harm. While patching is essential, the difficulty of securing legacy systems suggests that some exposed instances may remain vulnerable for an extended period, increasing the risk of targeted ransomware campaigns.

Expanded detail and Context are AI-generated analysis; the linked article remains the authoritative source.
Read the full article at BleepingComputer →
Related stories
Emergency hotfix issued for critical N-central remote code execution bug · Cybersecurity
Chrome Update Fixes Actively Exploited V8 Flaw · Cybersecurity
SonicWall SMA 1000 Flaws Under Active Exploitation; Rockwell Automation Patches Multiple Products · Cybersecurity
Google Urges Immediate Chrome Update to Patch 12 Vulnerabilities · Cybersecurity
This summary is AI-generated and original to Mobble; the linked article is the authoritative source. Original headline: “SAP warns of maximum severity 'OVERPASS' kernel vulnerability.” Browse more stories.