"A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative," Onapsis CTO JP Perez-Etchegoyen said.
OVERPASS (CVE-2026-44756): a maximum-severity kernel memory corruption
In its September 2026 security updates, SAP patched a maximum-severity memory corruption flaw in the SAP Kernel tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis researchers. Onapsis says the defect is a classic buffer overflow in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, producing full compromise of the underlying SAP processes and business data.
The vector for OVERPASS is SAP Internet Communication Manager (ICM), the networking component of the SAP Application Server that connects the SAP NetWeaver Application Server to the Internet via HTTP, HTTPS, and SMTP. Because the vulnerable code sits in kernel-level processing tied to ICM, a successful exploit can be executed over standard web-facing channels.
S4GET (CVE-2026-58240): NetWeaver Message Server missing authentication
SAP also addressed CVE-2026-58240, labeled S4GET by Onapsis Research Labs. Onapsis describes this as a critical missing-authentication vulnerability in the SAP NetWeaver Message Server that, when successfully exploited, allows unauthenticated attackers to access an entire SAP system cluster and execute malicious payloads and arbitrary commands remotely across the network.
Onapsis security researcher Pablo Artuso explained the operational implication plainly: "The flaw is triggered through the same public port that every SAP GUI client connects to, so it cannot be firewalled away without breaking the end-user logon." Artuso added that exploitation "requires no credentials, no certificate, and no pre-existing misconfiguration. A successful attack yields full remote code execution as <sid>adm, the OS-level user that runs SAP, on every application server in the cluster."

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildExposure and scale: more than 10,000 Internet-facing SAP systems
Onapsis supplied the most concrete measure of potential scale: an estimate of over 10,000 Internet-facing SAP systems that use the vulnerable component. Perez-Etchegoyen noted that figure is conservative, saying it counts only HTTP-reachable systems and undercounts instances behind SAP Web Dispatcher proxies that return no distinguishing SAP banner on their root path and are therefore difficult for Internet-wide scanners to attribute.
The combination of a kernel-level memory corruption exploitable via ICM and an unauthenticated, cluster-wide command execution pathway in NetWeaver increases the attack surface for any exposed SAP installation. The company profile in the advisory underscores the stakes: SAP reported total revenues exceeding €36 billion in fiscal year 2025 and provides services to 99 of the 100 largest companies worldwide.
Recent pattern and risk signals: active exploitation and CISA listings
The new fixes follow a pattern that security teams will recognize. Last month SAP patched another maximum-severity vulnerability, CVE-2026-58231 in the Commerce Cloud e-commerce platform, which the threat intelligence company Defused flagged as being actively exploited days after the patch was released. Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP security flaws to its list of actively exploited vulnerabilities, including three that were abused by ransomware gangs.
Those incidents are the concrete precedent Onapsis and SAP point to when urging rapid mitigation: when critical, internet-reachable SAP components have exploitable flaws, real-world exploitation can follow quickly.
What this means for technologists, affected enterprises, and policymakers
- Technologists and security teams: apply the September 2026 SAP security updates for the Kernel and NetWeaver Message Server without delay; note that the NetWeaver Message Server flaw cannot simply be blocked at a network perimeter without disrupting SAP GUI logons.
- Affected enterprises and procurement leaders: prioritize inventory and exposure assessments for Internet-facing SAP endpoints, especially instances reachable via ICM and those returning SAP web interfaces; the reported estimate of more than 10,000 public IPs indicates sizable, measurable exposure.
- Policymakers and regulators: the recent pattern of post-patch exploitation and CISA's list of SAP flaws underlines the continuing operational risk these vulnerabilities pose to critical enterprise services, including those that serve the largest global companies.
Beyond its immediate technical severity, the pair of patches released in September 2026 joins a string of fast-moving events: a maximum-severity Commerce Cloud fix followed by reported active exploitation days later, and a multi-year CISA record of SAP flaws being weaponized. For organizations running SAP, the arithmetic is simple and stark — internet-reachable SAP components plus critical vulnerabilities equals an urgent patching imperative. Whether attackers will mount widespread exploitation of OVERPASS or S4GET remains to be seen, but the recent track record makes swift mitigation the pragmatic choice.




