SAP’s September 2026 Security Patch Day includes a maximum-severity vulnerability in the SAP Kernel tracked as CVE-2026-44756 and dubbed OVERPASS by Onapsis. The flaw carries a CVSS score of 10.0 and affects SAP Extended Passport processing across multiple kernel and Web Dispatcher releases. According to SAP, the vulnerability is a memory-corruption issue, while Onapsis describes the underlying weakness as a classic buffer overflow in the Extended Passport Protocol processing library. Successful exploitation can allow an unprivileged attacker to execute arbitrary commands with administrative privileges on the affected SAP host, potentially resulting in complete compromise of SAP processes and the business data they handle. SAP lists affected components across KRNL64NUC, KRNL64UC, KERNEL and WEBDISP releases and is urging customers to apply Security Note 3747649 with priority.
What makes CVE-2026-44756 particularly serious is that exploitation can occur through SAP Internet Communication Manager, or ICM, the component responsible for handling HTTP, HTTPS and SMTP communications between SAP NetWeaver Application Server and external systems. This places the vulnerable processing logic close to one of the most exposed parts of an SAP environment. Onapsis estimates that more than 10,000 unique internet-facing SAP systems expose web interfaces potentially associated with the vulnerable component, although that figure should not be interpreted as 10,000 confirmed vulnerable systems because internet visibility alone does not establish the exact installed kernel version or patch status.
The architectural position of the flaw is what gives OVERPASS such a large potential blast radius. SAP Kernel is not an optional business module sitting at the edge of an implementation. It provides core runtime functionality underneath SAP applications. A vulnerability at that layer can therefore affect many business processes regardless of whether the organization primarily uses SAP for finance, HR, manufacturing, supply chain or another function. Once an attacker gains administrative execution within the SAP host context, they may be able to access credentials, configuration, application data and interfaces connected to other enterprise systems.
The Extended Passport Protocol itself is designed to carry identity and authentication context between SAP components. That makes the presence of a memory-safety flaw in its processing particularly sensitive. Security mechanisms such as authentication protocols routinely process input that crosses system boundaries, and therefore their parsing code has to assume that received data may be hostile. A buffer overflow at this layer creates the possibility that data intended merely to describe identity information can instead manipulate memory inside a privileged process.
This is a useful example of why security protocols and secure transport do not automatically make the implementation secure. An organization might enforce HTTPS, strong SAP authentication and tightly managed user accounts, but those controls do little against a vulnerability that occurs while the server is parsing attacker-controlled protocol data before normal authorization becomes useful. When the flaw exists underneath the authentication model, strengthening passwords or adding another user-access policy cannot compensate for the vulnerable code path.
The remote exposure makes the issue more urgent. SAP systems have historically been treated as internal enterprise applications, but modern architectures increasingly expose SAP web services, Fiori applications, APIs and integration endpoints to partners, mobile users and cloud services. The more directly reachable the ICM or Web Dispatcher becomes, the more important it is to ensure that the underlying kernel is patched. Network teams should therefore identify every SAP system with public exposure rather than assuming that SAP infrastructure remains buried safely inside the corporate network.
Organizations should not rely solely on conventional web application firewalls either. OVERPASS is a memory-corruption vulnerability in SAP’s protocol-processing stack, not a typical SQL injection or cross-site scripting issue in a business application. A WAF may provide some visibility or virtual-patching capability if a reliable exploit signature becomes available, but it cannot safely replace the vendor correction. The definitive remediation is to deploy the SAP kernel or Web Dispatcher version containing the fix specified in Security Note 3747649.
The absence of public evidence of exploitation at disclosure time should not materially reduce patching urgency. Onapsis and SAP have already provided the vulnerable component, severity, affected release families and the broad exploitation consequence. Once a patch is public, attackers can compare fixed and vulnerable binaries to identify the changed logic and begin developing exploit techniques. That patch-diffing window is particularly dangerous for a remotely reachable memory-corruption flaw with a CVSS score of 10.0.
OVERPASS also arrives alongside CVE-2026-58240, dubbed S4GET, another critical SAP NetWeaver vulnerability disclosed in the same September update. S4GET is a missing-authentication flaw affecting the NetWeaver Message Server and carries a CVSS score of 9.8. According to Onapsis, an unauthenticated attacker can potentially access the SAP cluster and execute commands as the `adm` operating-system user on application servers. The flaw is reachable through the same message-server port used by legitimate SAP GUI clients, which makes simple firewall blocking operationally difficult without disrupting normal logon functionality.
The presence of both vulnerabilities in the same patch cycle is important because it demonstrates the amount of privilege concentrated within SAP infrastructure. One flaw targets kernel-level protocol processing, while another affects cluster messaging and authentication. Both can potentially provide attackers with administrative execution inside systems that organizations rely upon for critical business processes. This is why SAP security patching should not be treated as routine application maintenance comparable to updating an ordinary desktop utility.
Organizations should begin with an authoritative inventory of SAP kernel, Web Dispatcher and NetWeaver releases rather than attempting to infer vulnerability status from application names. SAP’s September bulletin lists numerous affected kernel versions, including long-lived 7.x branches and newer 8.x and 9.x releases. In large SAP estates, different application servers may run different kernel patch levels even when they belong to the same landscape. Remediation therefore needs to verify the actual binary level on every relevant host.
External exposure should then determine priority. Internet-facing ICM and Web Dispatcher systems should be patched first, followed rapidly by internal systems that can be reached from user, partner or application networks. Internal should not be equated with safe. If an attacker gains an initial foothold through phishing or another server, an unpatched internal SAP system may become a valuable lateral-movement target because of the data and privileges available behind it.
Network segmentation can provide useful defense in depth. SAP application servers should accept traffic only from networks and systems that genuinely require access. Administrative interfaces should be separated from user-facing services, and internal SAP communication ports should not be broadly reachable from ordinary workstation networks. The objective is to ensure that compromise of one endpoint does not automatically provide unrestricted access to every SAP service listening inside the enterprise.
Organizations should also maintain centralized SAP and operating-system telemetry. If an attacker successfully exploits a kernel vulnerability, unexpected process creation, command execution or outbound network activity originating from SAP service accounts such as `adm` may provide useful detection opportunities. Those accounts normally perform predictable application-server tasks. A shell, scripting interpreter or unusual network client spawned under an SAP administrative identity deserves immediate investigation.
Monitoring should extend to ICM and Web Dispatcher logs for unusual requests, repeated malformed traffic, unexplained process crashes and unexpected restarts. Memory-corruption exploits sometimes produce instability while attackers develop or test reliable exploitation. A sudden ICM or SAP process crash therefore should not automatically be treated as an ordinary availability issue when a critical remote memory-corruption vulnerability is publicly known.
External log retention is particularly important. If attackers obtain administrative execution on the SAP host, locally stored logs may no longer be completely trustworthy. Forwarding SAP, operating-system and network telemetry to an independent SIEM gives investigators a historical record outside the control of the compromised application server.
SAP customers should also prepare for the operational reality of kernel patching. Kernel updates often require testing because SAP landscapes contain custom code, integrations and business-critical workloads. But CVE-2026-44756 is precisely the type of vulnerability for which emergency procedures should already exist. Organizations should have pre-defined testing, rollback and maintenance processes that allow a critical kernel security update to be deployed without waiting for the normal quarterly application-maintenance cycle.
The September bulletin itself reinforces the wider patch-management challenge. SAP released 19 new security notes and one update to an earlier note on September 8, including CVE-2026-44756 at 10.0, CVE-2026-58240 at 9.8 and CVE-2026-76969 at 9.4. Enterprises therefore need risk-based prioritization rather than treating all SAP notes equally. Kernel-level unauthenticated or remotely reachable flaws should move immediately to the top of the queue.
The broader lesson from OVERPASS is that SAP systems should be viewed as critical computing infrastructure rather than merely business applications.
Their kernels process authentication, networking and application execution for systems that may control finance, payroll, manufacturing and supply-chain operations. A successful attacker does not need to understand every SAP transaction if they can compromise the runtime underneath them. That is what makes CVE-2026-44756 especially dangerous. A buffer overflow in an ordinary application can compromise that application. A buffer overflow in the SAP Kernel can put the platform hosting a large part of the business at risk.
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
Source: SAP warns of maximum severity 'OVERPASS' kernel vulnerability via Bleeping Computer — published 08 Sep 2026.
Was this article helpful?
Your feedback helps us improve the knowledge base.