certeu-2026-011

certeu
Description

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6].<br> Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6].<br> CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.<br>

Timeline
Published
Wed, 09 Sep 2026 15:07:59 CEST
Last Modified
Wed, 09 Sep 2026 15:07:59 CEST
CVSS Details

CVSS details not available.

Affected Products

No product information available.

References

No references available.

Linked Vulnerabilities

No linked vulnerabilities found.

{
  "datePublished": "Wed, 09 Sep 2026 15:07:59 CEST",
  "description": "On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6].<br>\nBoth are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6].<br>\nCERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.<br>",
  "id": "CERTEU-2026-011",
  "link": "https://cert.europa.eu/publications/security-advisories/2026-011/",
  "source": "certeu",
  "title": "2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server"
}
View JSON API Download JSON