SAP warns of maximum severity 'OVERPASS' kernel vulnerability
AdvisorySAP S/4HANAOnapsisSAP NetWeaverOur summary
SAP has released September 2026 security updates addressing 20 vulnerabilities, including a maximum-severity buffer overflow in the SAP Kernel dubbed OVERPASS. Identified as CVE-2026-44756 by Onapsis researchers, this flaw allows unprivileged attackers to gain administrative command execution on vulnerable hosts via the Internet Communication Manager. Additionally, SAP resolved CVE-2026-58240, a missing authentication issue in the NetWeaver Message Server known as S4GET, which permits remote code execution across entire system clusters without credentials. Onapsis estimates that over 10,000 internet-facing SAP systems are potentially exposed to these attacks.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.