Skip to main content
CybersecurityVulnerability Management

SAP Discloses Maximum-Severity Kernel Vulnerability

Close-up of industrial computer server in softly lit corporate data center.

"A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative," Onapsis CTO JP Perez-Etchegoyen said.

OVERPASS (CVE-2026-44756): a maximum-severity kernel memory corruption

In its September 2026 security updates, SAP patched a maximum-severity memory corruption flaw in the SAP Kernel tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis researchers. Onapsis says the defect is a classic buffer overflow in the Extended Passport Protocol (EPP) processing library. Successful exploitation lets unprivileged threat actors run arbitrary commands on vulnerable SAP hosts with administrative privileges, producing full compromise of the underlying SAP processes and business data.

The vector for OVERPASS is SAP Internet Communication Manager (ICM), the networking component of the SAP Application Server that connects the SAP NetWeaver Application Server to the Internet via HTTP, HTTPS, and SMTP. Because the vulnerable code sits in kernel-level processing tied to ICM, a successful exploit can be executed over standard web-facing channels.

S4GET (CVE-2026-58240): NetWeaver Message Server missing authentication

SAP also addressed CVE-2026-58240, labeled S4GET by Onapsis Research Labs. Onapsis describes this as a critical missing-authentication vulnerability in the SAP NetWeaver Message Server that, when successfully exploited, allows unauthenticated attackers to access an entire SAP system cluster and execute malicious payloads and arbitrary commands remotely across the network.

Onapsis security researcher Pablo Artuso explained the operational implication plainly: "The flaw is triggered through the same public port that every SAP GUI client connects to, so it cannot be firewalled away without breaking the end-user logon." Artuso added that exploitation "requires no credentials, no certificate, and no pre-existing misconfiguration. A successful attack yields full remote code execution as <sid>adm, the OS-level user that runs SAP, on every application server in the cluster."

Exposure and scale: more than 10,000 Internet-facing SAP systems

Onapsis supplied the most concrete measure of potential scale: an estimate of over 10,000 Internet-facing SAP systems that use the vulnerable component. Perez-Etchegoyen noted that figure is conservative, saying it counts only HTTP-reachable systems and undercounts instances behind SAP Web Dispatcher proxies that return no distinguishing SAP banner on their root path and are therefore difficult for Internet-wide scanners to attribute.

The combination of a kernel-level memory corruption exploitable via ICM and an unauthenticated, cluster-wide command execution pathway in NetWeaver increases the attack surface for any exposed SAP installation. The company profile in the advisory underscores the stakes: SAP reported total revenues exceeding €36 billion in fiscal year 2025 and provides services to 99 of the 100 largest companies worldwide.

Recent pattern and risk signals: active exploitation and CISA listings

The new fixes follow a pattern that security teams will recognize. Last month SAP patched another maximum-severity vulnerability, CVE-2026-58231 in the Commerce Cloud e-commerce platform, which the threat intelligence company Defused flagged as being actively exploited days after the patch was released. Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP security flaws to its list of actively exploited vulnerabilities, including three that were abused by ransomware gangs.

Those incidents are the concrete precedent Onapsis and SAP point to when urging rapid mitigation: when critical, internet-reachable SAP components have exploitable flaws, real-world exploitation can follow quickly.

What this means for technologists, affected enterprises, and policymakers

  • Technologists and security teams: apply the September 2026 SAP security updates for the Kernel and NetWeaver Message Server without delay; note that the NetWeaver Message Server flaw cannot simply be blocked at a network perimeter without disrupting SAP GUI logons.
  • Affected enterprises and procurement leaders: prioritize inventory and exposure assessments for Internet-facing SAP endpoints, especially instances reachable via ICM and those returning SAP web interfaces; the reported estimate of more than 10,000 public IPs indicates sizable, measurable exposure.
  • Policymakers and regulators: the recent pattern of post-patch exploitation and CISA's list of SAP flaws underlines the continuing operational risk these vulnerabilities pose to critical enterprise services, including those that serve the largest global companies.

Beyond its immediate technical severity, the pair of patches released in September 2026 joins a string of fast-moving events: a maximum-severity Commerce Cloud fix followed by reported active exploitation days later, and a multi-year CISA record of SAP flaws being weaponized. For organizations running SAP, the arithmetic is simple and stark — internet-reachable SAP components plus critical vulnerabilities equals an urgent patching imperative. Whether attackers will mount widespread exploitation of OVERPASS or S4GET remains to be seen, but the recent track record makes swift mitigation the pragmatic choice.

Original story at BleepingComputer