CVE-2026-58240
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.
⚡ Watch CVE-2026-58240
Get an email if CVE-2026-58240 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Advisory coverage (5)
- critical2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Servercert-eu · 2026-09-09
- unknownNCSC-2026-0356 [1.00] [M/H] Kwetsbaarheden verholpen in diverse SAP-productenncsc-nl · 2026-09-09
- high[NEU] [hoch] SAP Patch Day September 2026: Mehrere Schwachstellencert-bund · 2026-09-08
- criticalCVE-2026-58240: SAP NetWeaver Message Server does not sufficiently validate the authenticity of internal appli…nvd · 2026-09-08
- unknownMultiples vulnérabilités dans les produits SAP (08 septembre 2026)cert-fr-avis · 2026-09-08
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-58240)