SAP patches maximum-severity 'OVERPASS' kernel vulnerability, critical S4GET auth bypass

Over 10,000 internet-facing SAP systems potentially exposed to remote code execution attacks

edit
By LineZotpaper
Published
Read Time3 min
SAP has released its September 2026 security updates, addressing 20 vulnerabilities including two critical flaws: a maximum-severity memory corruption vulnerability in the SAP Kernel dubbed OVERPASS, and a critical authentication bypass in the NetWeaver Message Server named S4GET, which together could allow unauthenticated attackers to fully compromise SAP systems and access sensitive business data.

SAP’s latest patch batch covers a range of products, but two findings from security research firm Onapsis have drawn particular attention.

OVERPASS: Maximum severity kernel flaw

The first, tracked as CVE-2026-44756 and named OVERPASS, is a classic buffer overflow in the Extended Passport Protocol (EPP) processing library within SAP Kernel code. According to Onapsis, the vulnerability allows unprivileged attackers to execute arbitrary commands on vulnerable SAP hosts with administrative privileges, leading to full compromise of underlying SAP processes and data.

The flaw can be exploited over SAP Internet Communication Manager (ICM), the networking component that connects SAP NetWeaver Application Server to the internet via HTTP, HTTPS, and SMTP. Onapsis estimates that more than 10,000 internet-facing SAP systems use the vulnerable component and are potentially exposed.

“A targeted search using high-fidelity fingerprints identifies more than 10,000 unique Internet-facing IP addresses presenting an SAP web interface reachable from the public Internet, and that figure is conservative,” said Onapsis CTO JP Perez-Etchegoyen. “It counts only HTTP-reachable systems and materially undercounts the SAP Web Dispatcher, which proxies its backend and returns no distinguishing SAP banner on its root path, making it structurally hard for Internet-wide scanners to attribute.”

S4GET: Critical authentication bypass in NetWeaver Message Server

The second critical vulnerability, CVE-2026-58240 (dubbed S4GET), is a missing authentication flaw in SAP’s NetWeaver Message Server. After successful exploitation, unauthenticated attackers can access the entire SAP system cluster and execute malicious payloads and arbitrary commands remotely across the network.

Onapsis researcher Pablo Artuso explained the difficulty of defending against this attack: “The flaw is triggered through the same public port that every SAP GUI client connects to, so it cannot be firewalled away without breaking the end-user logon. Exploitation requires no credentials, no certificate, and no pre-existing misconfiguration. A successful attack yields full remote code execution as adm, the OS-level user that runs SAP, on every application server in the cluster.”

Last month, SAP fixed another maximum-severity vulnerability in its Commerce Cloud platform, which threat intelligence company Defused flagged as actively targeted in attacks. The September updates are available through SAP’s standard support channels; customers are urged to apply patches immediately.

§

Analysis

Why This Matters

  • The OVERPASS vulnerability gives unprivileged attackers full administrative control over SAP systems, potentially exposing confidential business data and operational processes.
  • Over 10,000 internet-facing SAP systems are estimated to be vulnerable, and the S4GET flaw cannot be mitigated by network firewalls without breaking legitimate user access, increasing urgency.
  • Given that a similar SAP Commerce Cloud flaw was recently exploited in active attacks, these vulnerabilities may attract threat actor interest.

Background

SAP is a German enterprise software company whose products are widely used by large organisations for enterprise resource planning, supply chain management, and human resources. The company regularly issues monthly security patches. The September 2026 update addresses 20 vulnerabilities, including two rated critical or maximum severity. Security firm Onapsis has a track record of discovering and disclosing SAP vulnerabilities, often providing remediation guidance alongside SAP’s patches.

Key Perspectives

[Onapsis researchers]: They identified and reported both flaws, warning that exploitation is straightforward and impactful. They estimate a large attack surface and stress that the S4GET vulnerability is particularly insidious because it uses a required network port that cannot be blocked. [SAP]: The company has released patches and will likely urge customers to apply them promptly. SAP typically coordinates disclosure with researchers and provides workarounds where possible. [Enterprise SAP customers]: The organisations running affected systems face a significant security risk. Many may have complex SAP environments with limited patching windows; the S4GET flaw’s lack of firewall workaround forces them to prioritise patching.

What to Watch

  • Whether security researchers or threat actors publish proof-of-concept exploits in the coming weeks, potentially increasing attack volume.
  • Reports of active exploitation of CVE-2026-44756 or CVE-2026-58240 from incident response firms or SAP’s own monitoring.
  • SAP’s next patch cycle in October — whether additional vulnerabilities in related components emerge as researchers continue to probe SAP’s networking stack.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.