“We’ll catch the next change window” turns into an incident when a CVSS 10 in the SAP kernel ships with a public exploitation toolkit — weeks after Patch Day.
“We’ll catch the next change window” turns into an incident.
OVERPASS (CVE-2026-44756) is unauthenticated remote code execution via malformed Extended Passport (EPP) data in shared kernel code. Onapsis also flagged S4GET (CVE-2026-58240, CVSS 9.8) on the NetWeaver Message Server. SAPMAP now ships PoCs for both.
Don’t Miss the Policy Changes That Affect Security Decisions
Get the key CISA actions, new regulations, guidance, and risk shifts in a quick daily brief.
By subscribing you agree to our Privacy Policy.
Free. Weekday mornings. 5 minutes or less.
What happened
SAP’s September 8, 2026 Patch Day included HotNews Note 3747649 for OVERPASS: missing boundary validation when deserializing EPP lets an unauthenticated attacker send a crafted request and achieve high-impact compromise (Onapsis: OS command execution as the SAP admin OS account). EPP is processed at session open — before auth — and is reachable over HTTP (ICM/Web Dispatcher), SAP GUI/DIAG, and RFC. One kernel patch closes all routes.
S4GET (Note 3759472, CVE-2026-58240) is missing authentication when the Message Server registers application-server components — unauth network attackers can register unauthorized components. It hits modern kernel family 9.16–9.20 (S/4HANA 2025 and earlier moves to those kernels).
Onapsis updated guidance through September 21: the SAPMAP toolkit includes PoC exploits for OVERPASS and S4GET. Onapsis had not observed in-the-wild exploitation as of that update — PoC publication is the clock speeding up.
Why it matters
Shared kernel code means ERP, S/4HANA, Solution Manager, PI/PO, portals, and Web Dispatcher inherit the flaw. Onapsis estimates 10,000+ Internet-facing SAP web interfaces as a conservative count — and the SAP GUI route exposes essentially every ABAP system internally even when nothing is published. Authorizations and SoD do not help: the bug runs before they evaluate. History (ICMAD, RECON, CVE-2025-31324) says SAP criticals get reverse-engineered fast once patches and toolkits are out.
What to do first
- Inventory every SAP system’s kernel release/patch level against Note 3747649 (and 3759472 for Message Server) — include non-prod and “forgotten” boxes.
- Patch Internet-facing ICM/Web Dispatcher / Fiori / WebGUI systems first; then internal app servers (GUI route is universal).
- RISE customers: file the downtime CSR promptly so the provider can schedule the kernel reboot.
- Apply FAQ Note 3776034 and HTTP-oriented workarounds in 3756304 only as temporary risk reduction — not a substitute for the kernel patch.
- Enable SAP application-layer monitoring for exploit attempts during rollout; preserve forensic evidence before wipe-and-patch if compromise is suspected.
Forward this — BASIS / SAP owners: patch Internet-facing ICM/Web Dispatcher systems against Note 3747649 first; PoCs are already in SAPMAP.
Details
- CVE-2026-44756 (OVERPASS): Memory corruption in EPP processing — CVSS 10.0 — Note 3747649
- CVE-2026-58240 (S4GET): Missing auth on Message Server registration — CVSS 9.8 — Note 3759472
- Vectors (OVERPASS): HTTP/ICM, SAP GUI/Dispatcher, RFC — all pre-auth
- PoC status: SAPMAP toolkit includes exploits (Onapsis, updated 2026-09-21)
- In-the-wild: Not observed by Onapsis as of latest advisory update
Hunt / verify
- Confirm kernel patch level matches Note 3747649 / 3759472 fixed builds post-change.
- Review Internet-facing SAP fingerprints and Message Server exposure; restrict Dispatcher behind SAProuter/jump hosts where possible.
- Watch for anomalous pre-auth traffic carrying abnormal EPP-related payloads and unexpected app-server registrations on the Message Server.
Slack paste: Confirm Note 3747649 / 3759472 kernel levels; patch Internet-facing ICM/Web Dispatcher first; watch pre-auth EPP + Message Server registrations.
Sources
- https://onapsis.com/blog/sap-overpass-remediation/
- https://onapsis.com/blog/sap-security-patch-day-september-2026/
- https://onapsis.com/blog/s4get-cve-2026-58240-sap-message-server-threat-advisory/
- https://support.sap.com/en/my-support/knowledge-base/security-notes-news/september-2026.html
- https://cert.europa.eu/publications/security-advisories/2026-011/
Start your morning with the signal that matters.
Get the biggest cybersecurity developments, why they matter, and where to go deeper on CyberExperts.
By subscribing you agree to our Privacy Policy.
Free. Weekdays. Built for operators.