SAP's September 2026 security update fixes 20 vulnerabilities, headlined by CVE-2026-44756, a critical buffer overflow in the SAP Kernel's Extended Passport Protocol library dubbed OVERPASS by Onapsis researchers. The bug allows unprivileged attackers to remotely execute commands with admin rights via SAP's Internet Communication Manager, and Onapsis estimates over 10,000 internet-facing SAP systems are exposed. SAP also patched CVE-2026-58240, dubbed S4GET, a missing authentication issue in the NetWeaver Message Server that lets unauthenticated attackers compromise an entire SAP cluster.
bleepingcomputer.com
· 2026-09-08
A commentary piece examines why large companies remain stuffed with sprawling, disorganized software stacks—from SAP and Workday to countless spreadsheets and scripts—despite growing AI capabilities. It challenges the Silicon Valley assumption that generative AI will let anyone instantly build custom tools to replace this mess, arguing that most workers aren't tool-builders and don't think in terms of reinventing their workflows.
ben-evans.com
· 2026-09-06
Jabil executive Harish described the manufacturer's strategy of simplifying its technology stack before layering on AI and cloud innovation. The company is consolidating processes onto SAP as its core digital platform and centering integrations around SAP's BTP and Integration Suite rather than juggling multiple point-solution tools.
technologyreview.com
· 2026-09-02
New SAP research shows 62% of C-suite executives are unhappy with how poorly their people and business performance data are integrated. While half of organizations plan for AI's effect on productivity, only 21% plan for its impact on job design and organizational structure, exposing a major disconnect between HR, finance and procurement systems.
venturebeat.com
· 2026-09-01