CVE Tools

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

BleepingComputerBy Sergiu Gatlan

AdvisorySAP S/4HANAOnapsisSAP NetWeaver

Our summary

SAP has released September 2026 security updates addressing 20 vulnerabilities, including a maximum-severity buffer overflow in the SAP Kernel dubbed OVERPASS. Identified as CVE-2026-44756 by Onapsis researchers, this flaw allows unprivileged attackers to gain administrative command execution on vulnerable hosts via the Internet Communication Manager. Additionally, SAP resolved CVE-2026-58240, a missing authentication issue in the NetWeaver Message Server known as S4GET, which permits remote code execution across entire system clusters without credentials. Onapsis estimates that over 10,000 internet-facing SAP systems are potentially exposed to these attacks.

Read at BleepingComputer

BleepingComputer publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store