rootpwn

Advisories

SAP Exposes Critical Kernel & Message Server Flaws: CVE-2026-44756 & CVE-2026-58240

SAP’s September Security Patch Day revealed two critical vulnerabilities that can be exploited remotely without authentication. The memory‑corruption flaw in SAP Extended Passport (OVERPASS, CVE‑2026‑44756) and the missing‑auth bug in NetWeaver Message Server (S4GET, CVE‑2026‑58240) both allow attackers to run arbitrary OS commands as the SAP installation user, risking full system takeover. Immediate application of SAP Security Notes 3747649 and 3759472 is mandatory.

On September 8, 2026, SAP rolled out its Security Patch Day updates, addressing two high‑severity flaws that threaten a wide array of SAP environments.

CVE‑2026‑44756 – “OVERPASS”

  • Memory corruption in the SAP Extended Passport (EPP) processing module.
  • Rated CVSS 10.0, the bug can be triggered remotely without any authentication.
  • Successful exploitation grants the attacker the ability to execute arbitrary operating‑system commands under the SAP installation account.

CVE‑2026‑58240 – “S4GET”

  • Missing authentication check in the SAP NetWeaver Message Server.
  • CVSS score of 9.8, also remotely exploitable without credentials.
  • Allows attackers to run OS commands as the SAP installation user, leading to a full compromise of the affected system.
Both vulnerabilities expose a single, dangerous outcome: complete takeover of the host and the data it protects.

In light of these findings, CERT‑EU urges all SAP customers to apply the following Security Notes without delay:

  • Security Note 3747649 – fixes the OVERPASS flaw.
  • Security Note 3759472 – patches the S4GET issue.

Failure to patch could leave critical business data exposed to remote attackers capable of executing any command on the underlying operating system.

SAP CVE Memory Corruption NetWeaver Remote Exploit Security Patch CERT-EU

← All news