2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
- Actief misbruik
- Niet bevestigd
- Hoogste CVSS
- 10,0 kritiek
- Kans op misbruik (EPSS)
- 0,7%
- Prioriteit
- 15 van 100
Uit de melding
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3].0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3].
8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6].
Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6].
CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.
Lees de volledige melding bij CERT-EU Security AdvisoriesBron: CERT-EU Security Advisories, CC BY 4.0, samengevat en vertaald door Seinwacht.