CVE Tools

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

The Hacker NewsBy The Hacker News

PatchSAP Extended Passport (EPP)SAP NetWeaver Message Server

Our summary

SAP has released security updates addressing multiple critical vulnerabilities, most notably CVE-2026-44756, a CVSS 10.0 memory corruption flaw in the SAP kernel's Extended Passport (EPP) processing. Identified by Onapsis as "OVERPASS," this defect allows unauthenticated attackers to achieve remote code execution with administrative privileges via crafted network requests, potentially compromising business data across SAP S/4HANA and other ABAP-based systems. Additionally, SAP patched CVE-2026-58240 (CVSS 9.8), a missing authentication check in the NetWeaver Message Server dubbed "S4GET" by researchers, along with two other high-severity issues affecting CAP and SAP GUI for Java. Although no active exploitation has been confirmed, administrators are urged to patch internet-facing systems urgently since traditional access controls do not mitigate these kernel-level defects.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store