CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

September 9, 2026

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution Ravie LakshmananSep 09, 2026Vulnerability / Enterprise Security SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP security company Onapsis, it has been codenamed OVERPASS. The flaw, which resides in the SAP kernel's processing of the Extended Passport (EPP), is exploitable remotely and without authentication, and allows bad actors to run arbitrary operating system commands on the SAP host with SAP administrative privileges,…

CVEs: CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768