THREATOPS
THREAT OPSThreat News › 2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

medcert_euPublished 2026-09-09

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclos

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://cert.europa.eu/publications/security-advisories/2026-011/