Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
SAP Addresses Critical Vulnerability in Passport Processing

SAP Addresses Critical Vulnerability in Passport Processing

Posted on September 8, 2026 By CWS

SAP has released a set of 20 new and updated security notes, addressing a critical memory corruption vulnerability among other issues. This high-severity flaw, identified as CVE-2026-44756 and scoring the maximum of 10 on the CVSS scale, involves a memory corruption problem within Extended Passport (EPP) Processing.

Understanding the Critical Vulnerability

The vulnerability, termed OVERPASS, arises from the absence of boundary validations during the deserialization of EPP data. This could lead to unsafe memory operations when processing externally supplied length fields, as explained by the application security firm Onapsis. Exploitation of this flaw could allow attackers to execute arbitrary system commands, access sensitive database credentials and password hashes, and manipulate live user sessions and configurations.

The defect is embedded within the SAP kernel code, impacting various SAP components since EPP is used for tracing across multiple SAP applications. The vulnerability is activated when a new user session is initiated, spanning multiple communication protocols. Onapsis notes that SAP’s control mechanisms are evaluated after the vulnerability is exploited, posing significant security risks.

Impact on SAP Systems and Components

The affected components include major SAP products like S/4HANA, ERP, Business Suite (ECC), NetWeaver, and others. The vulnerability can be exploited through multiple vectors, such as web requests, the SAP GUI protocol, and Remote Function Call (RFC) connections. The compromised components operate under the operating system account managing the SAP installation, granting attackers substantial control over the system.

Fortunately, there are no indications so far that the vulnerability has been exploited in real-world scenarios. Neither SAP nor Onapsis reports any in-the-wild exploitation attempts, alleviating some immediate concerns.

Additional Security Concerns and Solutions

In addition to the critical flaw in EPP Processing, SAP’s latest patches address three other critical vulnerabilities. These include a missing authentication check in NetWeaver, identified as CVE-2026-58240, which could permit unauthorized remote access. Another flaw, CVE-2026-76969, involves credential disclosure in multitenant applications using the Cloud Application Programming Model (CAP). Additionally, CVE-2026-66768 addresses improper access control issues in NetWeaver.

SAP’s September 2026 security patch also tackles high-severity vulnerabilities in ABAP Developer Tools, Integration Suite, and other components, ensuring a comprehensive enhancement of SAP’s security framework.

Through these proactive measures, SAP demonstrates its commitment to maintaining robust security across its product suite, reinforcing trust among its users and stakeholders.

Security Week News Tags:ABAP systems, Authentication, CVE-2026-44756, ERP, Extended Passport Processing, NetWeaver, Onapsis, Patch, S4HANA, SAP, SAP kernel, Security, Vulnerability

Post navigation

Previous Post: Chainguard Reaches 1 Billion Build Manifests Milestone

Related Posts

Jamf to Go Private Following .2 Billion Acquisition by Francisco Partners Jamf to Go Private Following $2.2 Billion Acquisition by Francisco Partners Security Week News
Onyx Security Secures  Million to Enhance AI Control Onyx Security Secures $40 Million to Enhance AI Control Security Week News
FBI Alerts on M ATM Jackpotting Losses in 2025 FBI Alerts on $20M ATM Jackpotting Losses in 2025 Security Week News
Critical Dolby Vulnerability Patched in Android Critical Dolby Vulnerability Patched in Android Security Week News
AI Agent Security: Analysis of Top 100 and Key Findings AI Agent Security: Analysis of Top 100 and Key Findings Security Week News
Terra Security Raises  Million for AI Penetration Testing Platform Terra Security Raises $30 Million for AI Penetration Testing Platform Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • SAP Addresses Critical Vulnerability in Passport Processing
  • Chainguard Reaches 1 Billion Build Manifests Milestone
  • BigBear 2.0 Phishing Tactic Evades Microsoft 365 MFA
  • Crypto Fraudsters Face Justice After $240M Bitcoin Heist
  • WeChat Security Flaw Exploited via Zero-Click Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • SAP Addresses Critical Vulnerability in Passport Processing
  • Chainguard Reaches 1 Billion Build Manifests Milestone
  • BigBear 2.0 Phishing Tactic Evades Microsoft 365 MFA
  • Crypto Fraudsters Face Justice After $240M Bitcoin Heist
  • WeChat Security Flaw Exploited via Zero-Click Worm

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark