SAP released September 2026 security updates to fix two highly dangerous flaws that could let attackers take over business systems. The most severe issue, CVE-2026-44756 ('OVERPASS'), is a CVSS 10.0 buffer overflow in SAP Kernel EPP processing that can be reached through Internet Communication Manager and lets an unprivileged attacker run commands as an SAP administrator. SAP also fixed CVE-2026-58240 ('S4GET'), a missing-authentication flaw in SAP NetWeaver Message Server that can allow unauthenticated remote code execution across an SAP cluster.
Why it matters: Many large organizations rely on SAP to run finance, HR, supply-chain, and other core operations, so compromise can expose sensitive business data and disrupt critical workflows. Organizations running exposed SAP systems should urgently apply SAP's September patches and review internet-facing NetWeaver and ICM components for exposure.
info@thehackernews.com (The Hacker News)
2026.09.09
98% relevant
This article appears to cover the same SAP September 2026 security event, specifically the CVSS 10.0 SAP kernel flaw dubbed OVERPASS that enables unauthenticated remote code execution, adding another report and likely patch context for the same disclosed vulnerabilities.
Sergiu Gatlan
2026.09.08
100% relevant
This article establishes a new trackable event: SAP's September 2026 release of fixes for CVE-2026-44756 and CVE-2026-58240, two newly named critical flaws with broad exposure risk across SAP environments.
Ionut Arghire
2026.09.08
97% relevant
This article is a direct report on the same September 2026 SAP patch event, adding technical detail on the OVERPASS flaw in Extended Passport Processing, its unauthenticated attack paths via web, SAP GUI, and RFC, affected SAP product families, and the related critical issues CVE-2026-58240, CVE-2026-76969, and CVE-2026-66768.
← Back to all stories