CVE Tools
Back to feed
Patch released SAP Kernel Onapsis ransomware SAP NetWeaver Message Server SAP

SAP Patches Critical Extended Passport Processing Vulnerability

SecurityWeek·By Ionut Arghire··2 min read
CVE Tools coverage

SAP has published emergency security updates addressing a critical memory corruption vulnerability, identified as CVE-2026-44756, within its Extended Passport (EPP) processing logic. Security researchers at Onapsis, who dubbed the defect "OVERPASS," warn that unauthenticated attackers can exploit this bug to execute arbitrary system commands, steal database credentials, and manipulate SAP binaries across various platforms including S/4HANA and ERP. The flaw exists because missing boundary validations during data deserialization occur before standard authorization controls are applied, effectively bypassing user locks and role-based restrictions.

Although SAP has not reported active exploitation in the wild, the severity of the issue—rated CVSS 10/10—demands immediate attention from administrators running affected kernel versions. The company also resolved three other high-priority issues, including CVE-2026-58240, which allows unregistered component registration in S/4HANA 2025 and earlier, alongside vulnerabilities affecting NetWeaver and cloud-capable applications.

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store