Vulnerability
Published 2026-09-08
Verified 2026-09-19

SAP OVERPASS kernel EPP memory corruption (CVE-2026-44756) CVSS 10; also S4GET CVE-2026-58240

SAP’s September 2026 security patch day (covered 8 September 2026 by BleepingComputer and SecurityWeek) includes CVE-2026-44756, a maximum-severity memory-corruption bug in Extended Passport (EPP) processing in the SAP kernel, dubbed OVERPASS by Onapsis. Missing boundary checks on externally supplied length fields during EPP deserialization can let unauthenticated attackers run OS commands as the SAP installation owner, recover DB credentials/password hashes, read live user sessions, and modify data/binaries. Onapsis says EPP is hit as a session opens (before authz controls), via web/ICM, SAP GUI, and RFC; products relying on the vulnerable kernel include S/4HANA, ERP/ECC, NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager and others. Onapsis estimates >10,000 internet-facing SAP web interfaces; no in-the-wild exploitation indicators reported for OVERPASS at publish. Same cycle: CVE-2026-58240 (S4GET) missing authentication on NetWeaver Message Server enabling unauth cluster RCE as <sid>adm; also critical CVE-2026-76969 (CAP credential disclosure) and CVE-2026-66768 (NetWeaver access control). Apply SAP Security Notes for September 2026 immediately; do not invent CVSS for sister CVEs beyond vendor/Onapsis statements. Primary research: Onapsis; wires: BleepingComputer / SecurityWeek.

Product
SAP kernel / Extended Passport (EPP); NetWeaver Message Server (S4GET)
Versions
Multiple SAP applications on vulnerable kernel builds (S/4HANA, ECC, NetWeaver, Web Dispatcher, etc.); S4GET: S/4HANA 2025 and earlier per Onapsis — apply September 2026 Security Notes
CVSS
10.0 (CVE-2026-44756, per SecurityWeek/Onapsis)
Exploited in Australia?
unknown
Patch to
Apply SAP September 2026 Security Notes for CVE-2026-44756 (OVERPASS) and CVE-2026-58240 (S4GET) and related critical notes; reduce internet exposure of ICM/Message Server where possible

Primary: BleepingComputer — SAP OVERPASS CVE-2026-44756 (8 Sep 2026) · Vendor: SAP Security Notes / patch day news · CVE: CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768 · SecurityWeek — OVERPASS (8 Sep 2026)

vulnerabilities cloud identity ot ics