What Changed
SAP’s September 2026 Patch Day, with Onapsis Research Labs, shipped Security Note 3747649 for OVERPASS (CVE-2026-44756): a memory-corruption bug in SAP Extended Passport (EPP) processing. Missing boundary validation during deserialization of externally supplied length fields lets an unauthenticated attacker send crafted network requests—malformed EPP / sap-passport-style headers—that corrupt kernel memory. Impact per SAP and Onapsis runs through arbitrary operating-system command execution under the SAP administrative OS account. The defective code sits in shared kernel paths used by ICM / NetWeaver ABAP and Java kernels and SAP Web Dispatcher 9.16 (other Web Dispatcher versions and HANA XS–bundled Web Dispatcher are called out as not affected in Onapsis’s summary). No credentials are required; the vulnerable path runs before authorization controls apply.
Same-cycle companion: S4GET (CVE-2026-58240, Note 3759472, CVSS 9.8)—a missing authentication check in the NetWeaver Message Server when registering internal application-server components. It affects modern 9.16 / 9.18 / 9.19 / 9.20 kernels. Onapsis notes the trigger rides the same public port SAP GUI clients use, so firewalling it without breaking logon is impractical.
Exposure estimate (labeled as estimate): Onapsis commentary relayed by BleepingComputer cites more than 10,000 unique Internet-facing IPs presenting an SAP web interface—described as conservative because it counts HTTP-reachable systems and undercounts Web Dispatcher. This is an Onapsis estimate, not a confirmed victim count, and primary coverage does not claim in-the-wild exploitation at disclosure.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
Free. Weekday mornings. 5 minutes or less.
Built from 100+ trusted cybersecurity sources.
Why This Matters Operationally
ERP kernels and Web Dispatchers are the business plane. Unauthenticated OS command execution on that plane is ransomware- and espionage-grade impact without a phishing foothold first. Pairing OVERPASS with same-day S4GET makes September’s SAP Patch Day two pre-auth cluster-compromise classes on core NetWeaver plumbing—not “average HotNews volume.”
What Defenders Should Verify First
- Apply Note 3747649 kernel corrections and SAPWEBDISP.SAR where Web Dispatcher 9.16 is in play.
- Apply Note 3759472 for Message Server / S4GET on 9.x kernels in the same change window when possible.
- Inventory internet-facing ICM and Web Dispatcher listeners; treat Onapsis’s >10k figure as a prioritization estimate, then validate your estate with internal asset data.
- Do not rely solely on HTTP workarounds for Web Dispatcher—workarounds are incomplete versus the kernel patch, and RFC / SAP GUI reachability remains.
- Keep urgency high despite no claimed ITW: absence of reports is not absence of risk on CVSS 10.0 pre-auth RCE.
Source Context
- SAP September 2026 Security Notes (3747649 / 3759472)
- Onapsis: SAP Security Patch Day September 2026
- BleepingComputer: SAP warns of maximum-severity OVERPASS (includes Onapsis >10k estimate)
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
Free. Weekday mornings. Unsubscribe anytime.
Built from 100+ trusted cybersecurity sources.