SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data. The flaw can be exploited over SAP Internet Communication Manager (ICM), the networking component of the SAP Application Server that connects the SAP System (SAP NetWeaver Application Server) to the Internet via HTTP, HTTPS, and SMTP. According to Onapsis' estimates, more than 10,000 Internet-facing SAP systems use the vulnerable component and are potentially exposed to attacks exploiting the CVE-2026-44756 flaw. "A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative," Onapsis CTO JP Perez-Etchegoyen said on Tuesday. "It counts only HTTP-reachable systems and materially undercounts the SAP Web Dispatcher, which proxies its backend and returns no distinguishing SAP banner on its root path, making it structurally hard fo...
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
Affected Software
Frequently Asked Questions
Which SAP systems are potentially exposed to CVE-2026-44756?
SAP systems using the vulnerable Extended Passport Protocol processing library may be exposed, particularly where SAP Internet Communication Manager is reachable from the Internet. Onapsis estimated that more than 10,000 Internet-facing SAP systems use the affected component.
What could an attacker do by exploiting OVERPASS?
An unprivileged attacker could run arbitrary commands on a vulnerable SAP host with administrative privileges. This could fully compromise SAP processes and associated business data.
How can the vulnerability be reached remotely?
The flaw can be exploited through SAP Internet Communication Manager, the SAP Application Server networking component that supports HTTP, HTTPS, and SMTP connectivity.
What remediation is available for this issue?
SAP addressed CVE-2026-44756 as part of its September 2026 security updates, which cover 20 vulnerabilities across multiple products.
Has CVE-2026-44756 been associated with exploitation?
The vulnerability is marked as exploited and was KEV-listed on September 8, 2026.