SAP Rushes Fix for Maximum-Severity 'Overpass' Flaw Affecting 10,000+ Systems
Security vendor Onapsis has warned that more than 10,000 internet-facing SAP systems may be vulnerable to a maximum severity flaw in the SAP kernel, tracked as CVE-2026-44756. The issue lies in how SAP Extended Passport (EPP) data is processed: missing boundary checks during deserialization can cause a memory safety violation when an attacker sends a crafted, malformed EPP header. Because this code is shared across the kernel, the flaw is reachable both through the SAP GUI that every user connects to and through the RFC layer that links SAP systems together.
Onapsis says the vulnerability can be exploited remotely without authentication, and successful exploitation could let an attacker run arbitrary operating system commands with SAP administrative privileges, potentially leading to full compromise of business data and processes. No active exploitation has been observed yet, but Onapsis warns this situation is likely to change quickly given the severity and reach of the flaw.
Separately, Onapsis is urging SAP customers to patch a second critical bug, CVE-2026-58240 (dubbed 'S4GET'), which carries a CVSS score of 9.8 and affects the Message Server in certain versions of SAP S/4HANA. This flaw could allow an attacker to gain access to an entire SAP system cluster and remotely execute malicious payloads or commands. Onapsis is urging all SAP customers to apply patches immediately, prioritising CVE-2026-44756.