Seinwacht
Terug naar meldingen
laagCERT-EU Security AdvisoriesAdvisory

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

Actief misbruik
Niet bevestigd
Hoogste CVSS
10,0 kritiek
Kans op misbruik (EPSS)
0,7%
Prioriteit
15 van 100

Uit de melding

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3].0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3].

8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6].

Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6].

CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.

Lees de volledige melding bij CERT-EU Security AdvisoriesBron: CERT-EU Security Advisories, CC BY 4.0, samengevat en vertaald door Seinwacht.

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server | Seinwacht