2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
Cybersecurity Classified by Officially
Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products [1][3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it [2][3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server [3][6].
Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds [2][6].
CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible [1].
CVE-2026-44756 is a memory corruption vulnerability in the SAP Kernel library that processes the Extended Passport (EPP), addressed by SAP Security Note 3747649 [1][4]. SAP's CVE record states that boundary validation is missing during the deserialisation of EPP data, and that an unauthenticated attacker can send a crafted network request containing a malformed EPP header, potentially resulting in undefined behaviour and abnormal program termination, with a high impact on confidentiality, integrity, and availability [2][3].
Onapsis, which reported the vulnerability, assesses that successful exploitation allows a remote attacker to execute arbitrary operating system commands on the SAP host with SAP administrative privileges, resulting in full compromise of the underlying SAP business data and processes [2].
This is an extract. The publication continues at the source.
Source: CERT-EU.
Read the original at the source: https://cert.europa.eu/publications/security-advisories/2026-011/
Officially imported this from CERT-EU’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.
This publication has changed since it was first published
2 versions recorded. The original is kept in full — nothing is overwritten.
- v2 imported change on current
- v1 as first published on
Provenance
- Organization
- CERT-EU — imported from official source
- Official source
- https://www.cert.europa.eu/publications/security-advisories-rss RSS
- Imported
- September 15, 2026 20:57
- Versions
- 2 recorded
- Identity
-
security-advisories-10948