SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
- ID
- 22688
- Status
- summarized
- Published
- 09 Sep 2026, 2:25 PM
- Fetched
- 09 Sep 2026, 5:37 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 3.0
- Created
- 09 Sep 2026, 5:38 PM
- Tags
- Audience
- developers
What happened
SAP patched CVE-2026-44756 (CVSS 10.0), a memory corruption flaw in SAP Extended Passport (EPP) kernel processing dubbed OVERPASS, enabling unauthenticated remote code execution with SAP admin privileges. The flaw is reachable via web, SAP GUI, and RFC layers without credentials, allowing attackers to read the SAP secure store, recover database credentials, and move laterally across SAP systems.
Why it matters
Only relevant if your organization or clients run SAP systems; if so, patch immediately since no single network control mitigates it across all reachable protocols. For the rest of the audience, this is not actionable.
Discussion angle
Brief mention only: how shared kernel code across multiple unauthenticated protocols makes segmentation ineffective — a lesson in designing protocol boundaries, but not something most attendees will ship against.