Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Europe Needs a Real Policy on Israel-Palestine

    September 8, 2026

    Ukrainian TV channel building hit by Russian drone as five killed in Kyiv

    September 8, 2026

    EU pursues closer Israel ties on air defense and space – POLITICO

    September 8, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Europe Needs a Real Policy on Israel-Palestine
    • Ukrainian TV channel building hit by Russian drone as five killed in Kyiv
    • EU pursues closer Israel ties on air defense and space – POLITICO
    • Here in Liverpool, buses are back under public control – and that’s great for the only people who really matter | Steve Rotheram
    • Reform UK would ban full-face coverings in public areas
    • Richard Kelly on Donnie Darko at 25: ‘It’s a Miracle That Any Movie Gets Made’
    • SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability
    • Sality botnet disrupted, but crypto-stealing malware remains
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, September 8
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKSeptember 8, 2026 Cybersecurity No Comments3 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.

    Tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis security researchers who reported it, the vulnerability stems from a classic buffer overflow weakness in the Extended Passport Protocol (EPP) processing library.

    Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of the underlying SAP processes and business data.

    The flaw can be exploited over SAP Internet Communication Manager (ICM), the networking component of the SAP Application Server that connects the SAP System (SAP NetWeaver Application Server) to the Internet via HTTP, HTTPS, and SMTP.

    According to Onapsis’ estimates, more than 10,000 Internet-facing SAP systems use the vulnerable component and are potentially exposed to attacks exploiting the CVE-2026-44756 flaw.

    “A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative,” Onapsis CTO JP Perez-Etchegoyen said on Tuesday.

    “It counts only HTTP-reachable systems and materially undercounts the SAP Web Dispatcher, which proxies its backend and returns no distinguishing SAP banner on its root path, making it structurally hard for Internet-wide scanners to attribute.”

    S4GET, logic flaw in SAP’s NetWeaver Message Server

    Today, SAP also addressed CVE-2026-58240, a critical missing authentication vulnerability in the SAP NetWeaver Message Server named S4GET by Onapsis Research Labs.

    After successful exploitation, unauthenticated attackers can access the entire SAP system cluster and execute malicious payloads and arbitrary commands remotely across the network.

    “The flaw is triggered through the same public port that every SAP GUI client connects to, so it cannot be firewalled away without breaking the end-user logon,” Onapsis security researcher Pablo Artuso explained.

    “Exploitation requires no credentials, no certificate, and no pre-existing misconfiguration. A successful attack yields full remote code execution as adm, the OS-level user that runs SAP, on every application server in the cluster.”

    Last month, SAP fixed another maximum-severity vulnerability (CVE-2026-58231) in the Commerce Cloud cloud-based e-commerce platform, which threat intelligence company Defused flagged as actively exploited in attacks days after it was patched.

    Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP security flaws to its list of actively exploited vulnerabilities, including three that were abused by ransomware gangs.

    SAP is a German multinational software company that reported total revenues exceeding €36 billion in fiscal year 2025 and provides services to 99 of the 100 largest companies worldwide.


    article image

    Overall prevention scores can hide what happens after initial access. Once attackers are using valid credentials, prevention drops sharply.

    The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.

    Get the report

    Kernel Maximum OVERPASS SAP severity Vulnerability warns
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Adobe fixes critical Magento zero-day exploited to backdoor servers

    Hackers build AI frameworks for widescale credential theft

    Sudan’s healthcare system on brink of collapse, MSF warns | Health News

    Why CISOs should focus on real AI threats, not hype

    Mathspace Data Breach Exposes Over 1 Million People

    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Europe Needs a Real Policy on Israel-Palestine

    September 8, 2026

    Ukrainian TV channel building hit by Russian drone as five killed in Kyiv

    September 8, 2026

    EU pursues closer Israel ties on air defense and space – POLITICO

    September 8, 2026

    Here in Liverpool, buses are back under public control – and that’s great for the only people who really matter | Steve Rotheram

    September 8, 2026
    Latest Posts

    Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

    August 1, 2026

    AI in Formula One: Competitive advantage is all about the human in the loop

    August 1, 2026

    Pedro Sánchez hits out at EU leaders over criticism of Spain’s migrant crisis

    August 1, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Europe Needs a Real Policy on Israel-Palestine

    September 8, 2026

    Ukrainian TV channel building hit by Russian drone as five killed in Kyiv

    September 8, 2026

    EU pursues closer Israel ties on air defense and space – POLITICO

    September 8, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.