Tech News
← Home  ·  All topics

Overpass

1 GoKawiil brief on this topic

SAP patches maximum-severity OVERPASS kernel flaw affecting 10,000+ systems

SAP's September 2026 security update fixes 20 vulnerabilities, headlined by CVE-2026-44756, a critical buffer overflow in the SAP Kernel's Extended Passport Protocol library dubbed OVERPASS by Onapsis researchers. The bug allows unprivileged attackers to remotely execute commands with admin rights via SAP's Internet Communication Manager, and Onapsis estimates over 10,000 internet-facing SAP systems are exposed. SAP also patched CVE-2026-58240, dubbed S4GET, a missing authentication issue in the NetWeaver Message Server that lets unauthenticated attackers compromise an entire SAP cluster.