CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-58240

criticalCVSS 9.8covered by 5 sourcesfirst seen 2026-09-08
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.

⚡ Watch CVE-2026-58240

Get an email if CVE-2026-58240 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (5)

External references

NVD record for CVE-2026-58240

CVE.org record

Embed the live status

CVE-2026-58240 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-58240 status](https://www.csirts.com/badge/CVE-2026-58240)](https://www.csirts.com/cve/CVE-2026-58240)