2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.
More from CERT-EU
- 2026-012: Critical Vulnerabilities in Check Point Products
- 2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway
- 2026-009: Critical Vulnerabilities in Microsoft SharePoint
The rest of this wire is for subscribers
Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.
7 days, no card required.
Read releases like this the second they cross the wire.
1,200+ — live on PPN World right now. Every release from this source, the moment it crosses — plus 80+ other newswires, saved searches and instant alerts.
Start the free trial →Your announcement next? Distribute your press release to the global wires with PPN Source — and track its pickup live here.
PPN Source →