SAP Patches Critical Unauthenticated RCE Bugs
SAP Patches Critical Unauthenticated RCE Bugs
Summary
SAP released critical security updates on its September 2026 Patch Day addressing multiple vulnerabilities, two of which are of exceptional severity and were discovered and reported by SAP security firm Onapsis: CVE-2026-44756 ("OVERPASS") and CVE-2026-58240 ("S4GET"). Both vulnerabilities are remotely exploitable without authentication and can lead to full compromise of SAP systems. OVERPASS carries the maximum possible CVSS score of 10.0, while S4GET is rated at 9.8. While no in-the-wild exploitation has been observed, these flaws affect core SAP infrastructure components and warrant immediate patching.
Affected Systems and/or Applications
VulnerabilityCodenameCVSSAffected ComponentsVersionsCVE-2026-44756OVERPASS10.0SAP EPP Processing, shared by multiple componentsKRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20CVE-2026-58240S4GET9.8SAP NetWeaver Message Server9.16, 9.18, 9.19, 9.20
Key scope notes:
- OVERPASS exists in shared kernel code used by multiple protocols, making it reachable from the internet-facing web layer, the SAP GUI layer, and the RFC layer that links SAP systems together: none requiring credentials.
- S4GET is triggered through the same public port that every SAP GUI client connects to, meaning it cannot be firewalled away without breaking end-user logon.
Two other critical vulnerabilities, still of critical severity but rated lower than OVERPASS and S4GET, were also patched by SAP:
VulnerabilityCVSSDescriptionAffected ComponentsVersionsCVE-2026-769699.4Credential disclosure in multitenant applications using SAP Cloud Application Programming Model (CAP)Library - sap/cds-mtxs<=1.18.3, <=2.7.6, <=3.9.6, <=4.0.2CVE-2026-667689.0Improper Access Control in SAP NetWeaver (SAP GUI for Java)SAP NetWeaver (SAP GUI for Java)BC-FES-JAV 8.10
SAP customers should also review the rest of the September Patch Day notes in their entirety and evaluate the need for further patching.
Technical Details
CVE-2026-44756 / "OVERPASS" (CVSS 10.0)
OVERPASS is a memory corruption vulnerability residing in the SAP kernel's processing of the Extended Passport (EPP). The flaw stems from missing boundary validation during the deserialization of EPP data, resulting in a memory safety violation when processing externally supplied length fields.
- Attack vector: An unauthenticated attacker sends crafted network requests containing a malformed EPP header to an affected system.
- Impact: The attacker can take control of the receiving process and run arbitrary operating system commands on the SAP host with SAP administrative privileges, leading to total compromise of underlying SAP business data and processes.
- Reachability: Because EPP processing is shared kernel code used by more than one protocol, the flaw is reachable through several SAP components and several communication protocols, including the web, SAP GUI, and RFC layers, with no single network control capable of fully mitigating risk.
"SAP authorizations and Segregation of Duties (SoD) controls will not help. The vulnerable code runs before any authentication step, so locking users, tightening roles, enforcing password policies or restricting transaction access has no effect on this attack path." - Onapsis CTO JP Perez-Etchegoyen
CVE-2026-58240 / "S4GET" (CVSS 9.8)
S4GET is a logic flaw in the SAP NetWeaver Message Server involving a missing authentication check. The server insufficiently validates the authenticity of internal application server components during registration.
- Attack vector: An unauthenticated attacker with network access can register unauthorized components by interacting with the same public port used by SAP GUI clients.
- Impact: Successful exploitation yields full remote code execution as
<sid>adm, the OS-level user that runs SAP, on every application server in the cluster. - Reachability: The flaw is present across SAP's entire modern 9.x kernel family (the kernels that SAP S/4HANA and SAP S/4HANA Cloud Private Edition run on). Because it is triggered through the standard SAP GUI port, it cannot be blocked by firewalls without breaking legitimate end-user logon.
"What makes it uniquely dangerous is its reachability: the flaw is triggered through the same public port that every SAP GUI client connects to, so it cannot be firewalled away without breaking the end-user logon. Exploitation requires no credentials, no certificate, and no pre-existing misconfiguration." - Pablo 'Partu' Agustin Artuso, Onapsis
Mitigation
- Apply patches from SAP Security Notes immediately:
- Prioritize patching order:
- Patch internet-facing systems first, then internal instances.
- Systems processing sensitive business data and NetWeaver Message Server instances should receive priority attention.
- Reduce exposure where possible:
- Limit network exposure of SAP services to the extent operationally feasible.
- Note that firewalls alone cannot fully mitigate either vulnerability due to their reachability through standard SAP communication channels.
What the Cyber Fusion Center is Doing
The CFC is actively monitoring threat intelligence and reports related to OVERPASS and S4GET. This advisory will be updated if required.
References
- SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution — The Hacker News
- SAP Security Notes: September 2026 Patch Day — Onapsis
- SAP Security Updates September 2026 - Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport — Cybersecurity News
- SAP Security Patch Day - September 2026
.webp)

.avif)


.webp)

