SAP has issued security updates to fix multiple high‑severity flaws, including a maximum‑severity remote, unauthenticated memory corruption vulnerability in the SAP kernel’s Extended Passport (EPP) processing, tracked as CVE-2026-44756 (CVSS 10.0), codenamed OVERPASS. Discovered and reported by Onapsis, the flaw stems from missing boundary validation during EPP deserialization.
An unauthenticated attacker can send crafted network requests with a malformed EPP header to trigger a memory safety violation, potentially gaining remote code execution on the SAP host with SAP administrative privileges. SAP notes that OVERPASS is reachable from internet‑facing layers and multiple SAP components (web, GUI, RFC) and does not require credentials, meaning standard network controls may not fully mitigate risk.
Exploitation could allow reading the SAP secure store to obtain database credentials and password hashes, viewing live session data, extracting credentials to move laterally across SAP systems, and modifying application data, configurations, and binaries.
A second critical flaw patched is CVE-2026-58240 (CVSS 9.8) in the SAP NetWeaver Message Server, named S4GET by Onapsis. This unauthenticated vulnerability arises from a missing authentication check and can enable full remote code execution as the OS user <sid>adm on every application server in the cluster when exploited via the public SAP GUI port.
In addition, SAP lists two more high‑severity CVEs: CVE-2026-76969 (CVSS 9.4) affecting CAP multi‑tenant apps for credential disclosure, and CVE-2026-66768 (CVSS 9.0) in SAP NetWeaver SAP GUI for Java for arbitrary command execution. While none have been observed exploited yet, Onapsis advises inventorying SAP systems, prioritising internet‑facing patches, reducing exposure, and monitoring for exploitation attempts as rollout proceeds.