SAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP has released September 2026 security updates addressing 20 vulnerabilities, including a maximum-severity buffer overflow in the SAP Kernel dubbed OVERPASS. Identified as CVE-2026-44756 by Onapsis researchers, this flaw allows unprivileged attackers to gain administrative command execution on vulnerable hosts via the Internet Communication Manager. Additionally, SAP resolved CVE-2026-58240, a missing authentication issue in the NetWeaver Message Server known as S4GET, which permits remote code execution across entire system clusters without credentials. Onapsis estimates that over 10,000 internet-facing SAP systems are potentially exposed to these attacks.