SAP released its September 2026 security updates, led by CVE-2026-44756 (OVERPASS), a CVSS 10.0 memory-corruption vulnerability in Extended Passport Processing (EPP). The flaw results from inadequate boundary validation while deserializing EPP data in shared SAP kernel code; a crafted malformed EPP header can trigger unsafe memory handling. An unauthenticated remote attacker may execute operating-system commands with SAP privileges, access secrets and active sessions, and alter SAP data, configuration, or binaries before standard authorization controls apply.
The vulnerable code can be reached through web requests, SAP GUI, and RFC connections, making both internet-facing and internally exposed SAP environments relevant. SAP issued Security Note 3747649 and also published fixes for other critical issues affecting NetWeaver and multitenant Cloud Application Programming Model applications; the wider advisory covers several SAP products, including NetWeaver Message Server, GUI for Java, Integration Suite, and ABAP platforms. Organizations should promptly apply the supported kernel correction and all applicable September patches, then validate affected systems; no active exploitation of CVE-2026-44756 had been reported.

See real exploitation activity before you spend the cycle.
7 events from the most recent confirmed update back to the earliest known activity.
The Canadian Centre for Cyber Security issued advisory AV26-894 warning that multiple SAP products, including EPP, NetWeaver, CAP, SAP GUI for Java, and Integration Suite components, were affected. It advised users and administrators to review SAP's September Security Patch Day information and apply applicable updates.
SAP released Security Note 3747649 to remediate CVE-2026-44756 in affected SAP kernel, Web Dispatcher, and related releases. The correction addresses vulnerable EPP processing reachable via web, SAP GUI, and RFC communication paths.
CVE-2026-44756 was publicly published as a CVSS 10.0 memory-corruption flaw in SAP Extended Passport Processing. The flaw can be triggered by malformed EPP data and may permit unauthenticated remote code execution with SAP system privileges; no active exploitation was observed at the time.
During its September 2026 Patch Day, SAP updated Security Note 3771065 for CVE-2026-58231, a CVSS 10.0 improper-authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter that had initially been released in August. SAP stated that unmodified SAP Commerce Cloud environments are not exposed to the flaw by default.
SAP's September 2026 patch cycle delivered 20 new or updated security notes, including fixes for critical NetWeaver missing-authentication flaw CVE-2026-58240, CAP credential-disclosure flaw CVE-2026-76969, and NetWeaver access-control flaw CVE-2026-66768.
CVE-2026-44756, later designated OVERPASS by Onapsis, was reserved.
SAP released fixes for CVE-2026-58243, which could let attackers gain elevated privileges in SAP ABAP Developer Tools, and CVE-2026-2332, which could cause information disclosure in SAP Commerce Cloud.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
12 references tracked. Mallory keeps watching after this page renders.
heise.de
Open sourcelabs.beazley.security
Open sourcethecybersecguru.com
Open sourceinfosecurity-magazine.com
Open sourcesecurityweek.com
Open sourcethreataft.com
Open sourceonapsis.com
Open sourceonapsis.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.