www.infosecurity-magazine.com 9 Sept 2026, 08:15 UTC

Over 10,000 SAP Systems Exposed to Critical Kernel Flaw

CyberSIXT Evidence Panel

OVER 10,000 internet-facing SAP systems could be exposed to a maximum-severity vulnerability in the SAP kernel, according to Onapsis. The Onapsis Research Labs (ORL) disclosed the Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing, tracked as CVE-2026-44756.

The firm explained that missing boundary validation during deserialization of EPP data allows an unauthenticated attacker to send crafted network requests with a malformed EPP header, causing undefined behaviour and abnormal process termination. Because EPP processing is shared kernel code, the flaw is reachable from the SAP GUI layer and from the RFC layer that links SAP systems, and is remotely exploitable without authentication, existing by default in a range of SAP components.

Exploitation could enable remote attackers to run arbitrary OS commands on the SAP host with SAP administrative privileges, potentially leading to full compromise of SAP business data and processes. At the time of reporting, there was no active exploitation, though that status was expected to evolve.

Onapsis also highlighted additional critical SAP vulnerabilities requiring patches. CVE-2026-58240, dubbed “S4GET,” affects the Message Server in specific versions of SAP S/4HANA and could allow access to an entire SAP system cluster to remotely execute malicious payloads and arbitrary commands, with a CVSS of 9.8.

Two more notable flaws include CVE-2026-76969, a credential-disclosure issue in multitenant applications using SAP Cloud Application Programming Model (CAP) scored at 9.4 and patched with Security Note 3798315, and CVE-2026-66768, an improper access control vulnerability in SAP NetWeaver with a CVSS of 9.0 patched by SAP Security Note 3781729, which could enable arbitrary command execution on a victim’s machine. SAP customers are urged to patch CVE-2026-44756 immediately, alongside the others.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline