VulnerabilityBleeping Computer
10.0 — CRITICAL
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
🤖 AI BriefingAuto-generated threat analysis
🔍Threat Overview
SAP has addressed a maximum-severity 'OVERPASS' kernel vulnerability (CVE-2026-44756) and another critical missing authentication vulnerability in the SAP NetWeaver Message Server (CVE-2026-58240), both of which can be exploited over SAP Internet Communication Manager and SAP Commerce Cloud, respectively. The vulnerabilities allow unauthenticated attackers to run arbitrary commands on vulnerable SAP hosts with administrative privileges.
⚙️Technical Details
Affected Systems
SAP Internet Communication Manager and SAP Commerce Cloud
Attack Vectors
NETWORK
💥Impact Assessment
Severity: CRITICAL
Who Is at Risk
Internet-facing SAP systems using the vulnerable component, including more than 10,000 unique IP addresses
🛡️Recommended Actions
1Apply patches for CVE-2026-44756 and CVE-2026-58240 as soon as possible
2Implement additional security measures to prevent exploitation of the vulnerabilities
3Monitor SAP systems for signs of unauthorized access or malicious activity
📦Affected Products
SAP Internet Communication ManagerSAP Commerce Cloud
🔐NVD Verified DataVERIFIED
CVE-2026-44756 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-120
CVE-2026-58240 ↗CVSS 9.8 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HWeaknesses
CWE-308
CVE-2026-58231 ↗CVSS 10 — CRITICAL
Attack Vector
NETWORK
Complexity
LOW
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HWeaknesses
CWE-94
Read the full article
This is a curated summary. The complete article is available at Bleeping Computer.
