FR
live
Security Critical CVSS 10

SAP patches OVERPASS and S4GET, two pre-auth flaws that run code on the SAP kernel

On September 9, 2026, SAP shipped fixes for four critical flaws, including CVE-2026-44756 (CVSS 10.0), a memory-corruption bug in Extended Passport processing that yields unauthenticated remote code execution across three protocols at once. Basis teams should patch the SAP kernel first, ahead of any network segmentation effort.

A row of border-control ink stamps, one of them raised and dipped in a single amber ink pad.

September 9, 2026. SAP shipped its monthly security update and fixed four critical flaws, two of which share a dangerous property: they are reachable without authentication, remotely, and over ports you cannot close without breaking the business itself. The most severe, CVE-2026-44756 — nicknamed OVERPASS — scores a CVSS 10.0. Discovered by Onapsis, it allows arbitrary operating-system commands on the SAP host with administrative privileges. Why it matters: a pre-auth RCE in the SAP kernel is total compromise of business data, not a peripheral incident.

OVERPASS: memory corruption inside the Extended Passport

CVE-2026-44756 lives in the SAP kernel code that processes the Extended Passport, or EPP. The EPP is a metadata structure that accompanies calls between the layers of an SAP system — an internal identity stamp that travels with requests. The flaw is a memory corruption: a missing boundary validation during deserialization of EPP data leads to a memory-safety violation when the code processes externally supplied length fields.

In practice, an unauthenticated attacker sends a crafted network request carrying a malformed EPP header. The result is not a simple crash: the defect allows taking control of the receiving process and, from there, running operating-system commands on the host with SAP administrative privileges. Onapsis CTO JP Perez-Etchegoyen put the scope plainly: “A specially-crafted request sent to an affected system can be abused to take control of the receiving process and, from there, run operating system commands on the host.”

The severity comes from the reach of the shared code. EPP processing is kernel code used by more than one protocol, so the flaw is reachable from the internet-facing web layer, from the GUI layer every end user connects to, and from the RFC layer that links SAP systems to each other. Three protocols, three attack paths, none of them requiring credentials — which, in his words, means “no single network control can fully mitigate risk.”

What an OVERPASS exploitation is worth

A successful OVERPASS exploit opens access that goes far beyond the compromised machine. An attacker can read the SAP secure store to recover database credentials, password hashes and all hosted business data; read the live session data of logged-in users; extract stored credentials to move laterally into every other SAP system; and modify application data, system configuration and the SAP binaries themselves.

This is the scenario every CISO of an S/4HANA shop dreads: not an isolated incident, but the loss of the trust root that carries billing, payroll and production. When the kernel holding the database secrets is compromised, subsequent application patches no longer suffice — you must rebuild trust, and that is measured in weeks.

S4GET: the flaw you cannot firewall away

The second critical, CVE-2026-58240 (scored CVSS 9.8), is a missing authentication check in the SAP NetWeaver Message Server. Onapsis, which also discovered it, named it S4GET. It is a logic flaw, not a misconfiguration, present in the 9.x kernel lines — the ones running S/4HANA, S/4HANA Cloud Private Edition and potentially other ABAP-based products.

What makes S4GET uniquely dangerous is its reachability. According to researcher Pablo “Partu” Agustin Artuso, the flaw is triggered through the same public port every SAP GUI client connects to — the one you cannot close without blocking end-user logon. Exploitation requires “no credentials, no certificate, and no pre-existing misconfiguration.” A successful attack yields full remote code execution as sidadm, the OS-level user that runs SAP, on every application server in the cluster.

The sentence to remember: “it cannot be firewalled away without breaking the end-user logon.” For a Basis team that is the worst case — the classic network countermeasure is off the table, and the only remaining barrier is the patch itself.

Two more criticals in the same bundle

The September 9, 2026 release contains two further critical flaws, less publicized but just as real:

  • CVE-2026-76969 (CVSS 9.4) — a credential disclosure in multi-tenant applications using the SAP Cloud Application Programming Model (CAP), letting an unauthenticated attacker obtain sensitive credentials via crafted requests, then replace or delete tenant data;
  • CVE-2026-66768 (CVSS 9.0) — an improper access control in SAP GUI for Java that allows arbitrary command execution on the underlying host.

The overall picture is consistent: SAP is concentrating these fixes on the kernel layer and the interface components the enterprise exposes by nature — the Message Server, CAP, the GUI. That is not a calendar coincidence; it reflects an attack surface where the network boundary has already been bypassed by design.

What Basis teams should do

The priority is clear, and it is not network segmentation — it is the kernel patch. OVERPASS is pre-auth, multi-protocol and reachable from the web layer; S4GET is reachable from the port every GUI client uses. No firewall rule protects against either one.

The recommended order of action:

  • Inventory exposed systems — SAP Gateway, Fiori, Web Dispatcher servers, outward-facing RFC, and any S/4HANA host reachable from a partner network;
  • Apply today’s SAP notes on the kernel and the Message Server first, ahead of peripheral application fixes;
  • Check your kernel line — the 9.x lines (S/4HANA) are the S4GET scope, but OVERPASS hits the shared EPP-processing code beyond a single line;
  • Watch for exploitation signals — Onapsis will likely publish a full technical write-up; any in-the-wild activity will turn these CVSS scores into a KEV urgency.

The deeper lesson goes beyond SAP: when a flaw is reachable “through the port everyone uses,” perimeter defense is structurally behind. The only barrier that still holds is how fast you apply the patch.

Verdict

OVERPASS and S4GET are not business-application vulnerabilities you can mitigate while waiting for a maintenance window: they are flaws in the kernel and the Message Server, reachable without authentication through paths no firewall can close without stopping the enterprise.

If your fleet runs S/4HANA or a 9.x kernel line, apply this month’s SAP notes immediately, starting with hosts reachable from outside. Treat CVE-2026-44756 as a potential compromise of the trust root, not a routine patch: a successful exploit exposes the secure store and database credentials, which forces a rebuild of trust, not just a service restart.

If you cannot patch right away, your only margin is to physically isolate SAP hosts from every network not strictly required — knowing that, for S4GET, the GUI port must stay open, and that isolation only reduces the probability, never cancels it.

References

cve

Linked vulnerabilities

CVE-2026-44756A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application. Critical CVSS 10 08/09 CVE-2026-58240SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal application server components during registration. An unauthenticated attacker with network access to the affected service could exploit this weakness to register an unauthorized component and potentially perform unauthorized actions within the application environment, resulting in a high impact on the confidentiality, integrity, and availability of the affected system. Critical CVSS 9.8 08/09 CVE-2026-66768SAP GUI for Java does not correctly enforce the trust level policy for certain functions invoked from a connected backend system. A low-privileged attacker could exploit this weakness by manipulating a connected backend system to trigger affected functionality. This could allow arbitrary command execution on the victim's machine, leading to a high impact on the confidentiality, integrity, and availability of the affected system. Critical CVSS 9 08/09 CVE-2026-76969@sap/cds-mtxs NPM library does not perform sufficient checks on certain functionality used in multitenant CAP applications with extensibility enabled. An unauthenticated attacker could send specially crafted requests to obtain sensitive credentials and abuse them to replace or delete tenant data. Successful exploitation can result in a high impact on availability and integrity of the application. There may also be partial impact to the confidentiality of business data. Critical CVSS 9.4 08/09

The cyber brief, every Tuesday

The flaws that matter and the patches to apply, in a ten-minute read.

No spam. One-click unsubscribe.
read next

On the same topic

The Carbonato botnet turns exposed Docker daemons into Telegram-controlled AI agents

ThreatDown researchers reconstructed the Carbonato botnet, which compromises Docker daemons exposed on port 2375 and installs the open-source Hermes Agent framework with nothing but its persona file rewritten. Close port 2375, move to rootless or TLS, and revoke any AI API key sitting on a potentially affected host.

US soldier sentenced to 70 months for extorting ten telecom firms

On 28 September 2026, Cameron John Wagenius, aka kiberphant0m, was sentenced to 70 months in prison for hacking and extorting at least ten technology and telecommunications companies from his military base. The case is a reminder that insider threat and SSH brute-forcing remain an entry path as effective as any zero-day.

← Back to the feed

Type at least two characters.

↑ ↓ navigate ↵ open esc dismiss