AI Weekly Malaysia

Back to items Summaries

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

ID
22688
Status
summarized
Published
09 Sep 2026, 2:25 PM
Fetched
09 Sep 2026, 5:37 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
3.0
Created
09 Sep 2026, 5:38 PM
Tags
Audience
developers

What happened

SAP patched CVE-2026-44756 (CVSS 10.0), a memory corruption flaw in SAP Extended Passport (EPP) kernel processing dubbed OVERPASS, enabling unauthenticated remote code execution with SAP admin privileges. The flaw is reachable via web, SAP GUI, and RFC layers without credentials, allowing attackers to read the SAP secure store, recover database credentials, and move laterally across SAP systems.

Why it matters

Only relevant if your organization or clients run SAP systems; if so, patch immediately since no single network control mitigates it across all reachable protocols. For the rest of the audience, this is not actionable.

Discussion angle

Brief mention only: how shared kernel code across multiple unauthenticated protocols makes segmentation ineffective — a lesson in designing protocol boundaries, but not something most attendees will ship against.

Top