• News/
  • bleepingcomputer-20260908145520

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

BleepingComputer
·
Sergiu Gatlan
·
Published Sep 8, 2026
·
Updated

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data. The flaw can be exploited over SAP Internet Communication Manager (ICM), the networking component of the SAP Application Server that connects the SAP System (SAP NetWeaver Application Server) to the Internet via HTTP, HTTPS, and SMTP. According to Onapsis' estimates, more than 10,000 Internet-facing SAP systems use the vulnerable component and are potentially exposed to attacks exploiting the CVE-2026-44756 flaw. "A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative," Onapsis CTO JP Perez-Etchegoyen said on Tuesday. "It counts only HTTP-reachable systems and materially undercounts the SAP Web Dispatcher, which proxies its backend and returns no distinguishing SAP banner on its root path, making it structurally hard fo...

Read full article

Affected Software

5 affected components
SAP SAP Kernel=CVE-2026-44756
SAP Extended Passport Protocol (EPP) processing library=CVE-2026-44756
SAP SAP Internet Communication Manager (ICM)=CVE-2026-44756
SAP SAP NetWeaver Message Server (S4GET)=CVE-2026-58240
SAP SAP Commerce Cloud=CVE-2026-58231

Frequently Asked Questions

1

Which SAP systems are potentially exposed to CVE-2026-44756?

SAP systems using the vulnerable Extended Passport Protocol processing library may be exposed, particularly where SAP Internet Communication Manager is reachable from the Internet. Onapsis estimated that more than 10,000 Internet-facing SAP systems use the affected component.

2

What could an attacker do by exploiting OVERPASS?

An unprivileged attacker could run arbitrary commands on a vulnerable SAP host with administrative privileges. This could fully compromise SAP processes and associated business data.

3

How can the vulnerability be reached remotely?

The flaw can be exploited through SAP Internet Communication Manager, the SAP Application Server networking component that supports HTTP, HTTPS, and SMTP connectivity.

4

What remediation is available for this issue?

SAP addressed CVE-2026-44756 as part of its September 2026 security updates, which cover 20 vulnerabilities across multiple products.

5

Has CVE-2026-44756 been associated with exploitation?

The vulnerability is marked as exploited and was KEV-listed on September 8, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203