2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.
Details
Original advisory: https://cert.europa.eu/publications/security-advisories/2026-011/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-447560.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 25% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-582400.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-44756 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-58240 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- unknownNCSC-2026-0356 [1.00] [M/H] Kwetsbaarheden verholpen in diverse SAP-productenncsc-nl
- high[NEU] [hoch] SAP Patch Day September 2026: Mehrere Schwachstellencert-bund
- criticalCVE-2026-58240: SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal appli…nvd
- criticalCVE-2026-44756: A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing librar…nvd
- unknownMultiples vulnérabilités dans les produits SAP (08 septembre 2026)cert-fr-avis
Recent advisories for 2026-011
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalDrupal core - Moderately critical - Cross-site scripting - SA-CORE-2026-011drupal · 2026-07-15
More from CERT-EU Security Advisories
- critical2026-012: Critical Vulnerabilities in Check Point Products2026-09-10
- critical2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway2026-08-19
- critical2026-009: Critical Vulnerabilities in Microsoft SharePoint2026-07-23
- critical2026-008: Critical vulnerabilities in Ivanti Sentry2026-06-10
- critical2026-007: Critical Vulnerability in Windows Netlogon2026-06-10