INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SAP Patches Maximum Severity Overpass Flaw

| 2026-09-09 08:15 CRITICAL HIGH VULNERABILITY DISCLOSURE
Executive Summary
AI-generated
The discovery of the Memory Corruption vulnerability in SAP Extended Passport Processing, tracked as CVE-2026-44756, has sent shockwaves through the cybersecurity community. Onapsis Research Labs, a renowned security research firm, revealed that the flaw was exploited by multiple customers and could be patched with Security Note 3798315. The vulnerabilities, including credential disclosure flaws, improper access control vulnerabilities, and overpass flaws in SAP Patches Maximum Severity "Overpass" Flaw, pose significant risks to internet-facing systems and SAP customers worldwide. As of September 9th, Onapsis urged customers to take immediate action to patch the vulnerabilities, citing a CVSS score of 9.4 for one exploit and 9.0 for another. The incident highlights the importance of timely vulnerability disclosure and prompt patching in preventing devastating cyber attacks.
Technical Mitigations AI-generated
* Implement secure deserialization: Ensure that the SAP Extended Passport (EPP) Processing is properly validated and sanitized to prevent memory corruption vulnerabilities. * Patch CVE-2026-44756 immediately: Urgently patch the "Overpass" kernel vulnerability in SAP systems, as it can be exploited remotely without authentication and has a high CVSS score of 9.8. * Verify credentials before accessing SAP systems: Implement credential validation checks to ensure that only authorized users have access to SAP systems, particularly for multitenant applications using SAP Cloud Application Programming Model (CAP). * Monitor SAP system logs and network traffic: Continuously monitor SAP system logs and network traffic for suspicious activity or potential exploitation attempts. * Implement secure coding practices in SAP development: Ensure that developers follow secure coding practices when writing code for SAP systems, including proper input validation, sanitization, and error handling.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

se•••@bl•••.•••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
hxxp://••••••••••••••••••••
zt•••••.com
tr•••••.io
hu•••••.li
ww•••••.com
10•••••.jpg
10•••••.jpg
10•••••.jpg
10•••••.png
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
ShinyHuntersShinyHunters CVE-2026-44756CVE-2026-44756 CVE-2026-58231CVE-2026-58231 CVE-2026-58240CVE-2026-58240 CVE-2026-66768CVE-2026-66768 CVE-2026-76969CVE-2026-76969
Target & Sectors
DACH DACH NORTH_AMERICA NORTH_AMERICA
Incident Timeline
‎2016 August
Threat actors exploited a maximum severity "Overpass" flaw in SAP Patches to target Windows Server 2016.
tactic T1584.004 - Server
infrastructure Windows
infrastructure 2016 Windows Server
‎November 2021
Ransomware gangs exploited 14 SAP security flaws since November 2021.
tactic Ransomware
general_metric 14 SAP security flaws
‎fiscal year 2025
Threat actors exploited a maximum severity "Overpass" flaw in SAP Patches.
target_region Germany
financial €36 revenues
general_metric 100 largest companies
‎2026/08/09
Threat actors used a known maximum-severity vulnerability (CVE-2026-58231) in SAP's Commerce Cloud cloud-based e-commerce platform to gain full remote code execution on every application server.
vulnerability CVE-2026-58231
tactic Remote Code Execution
‎September 8
Threat actors exploited a vulnerability in SAP's Patches, specifically the "Overpass" flaw.
‎September 8, 2026
Threat actors used a known vulnerability in SAP's "OVERPASS" kernel to target the software.
organisation ThreatLocker
data_breach 0 September
‎2026/09/08
SAP addressed CVE-2026-58240, a critical missing authentication vulnerability in the SAP NetWeaver Message Server named S4GET.
vulnerability CVE-2026-58240
tactic T1584.004 - Server
organisation NetWeaver Message
‎September 2026
Threat actors exploited a maximum-severity memory corruption flaw in the SAP Kernel code.
organisation Microsoft
general_metric 966 flaws
general_metric 2 days
general_metric 20 vulnerabilities
‎2003 - 2026
Threat actors used a vulnerability in SAP Patches to target Social & Feeds.
organisation Social & Feeds
‎2026/09/09
SAP customers are urged to patch the "Overpass" kernel vulnerability, CVE-2026-44756.
organisation SAP the Memory Corruption
organisation SAP Extended Passport
organisation SAP Security Note
financial 3781729 Security Note
organisation the Extended Passport Protocol
organisation SAP Customers
organisation Patch Onapsis
organisation CVSS
organisation SAP Cloud Application Programming Model
organisation Security Note
organisation SAP NetWeaver
financial 3798315 Note improper control vulnerability
organisation SAP Patches Maximum Severity
organisation SAP
organisation OVERPASS
organisation RFC
organisation the Message
organisation ICM
organisation the SAP Application
organisation the SAP System
organisation SAP NetWeaver Application
organisation SMTP
infrastructure Microsoft 365
organisation BigBear Microsoft 365
organisation MFA
victims 258 organizations
organisation NetWeaver
organisation Google Workspace
organisation Microsoft Exchange
infrastructure Windows
organisation Stack Protection
organisation Windows Registry
organisation the Windows Registry
infrastructure Linux
organisation APM
organisation Hackers
organisation Magento
organisation Adobe
threat_actor ShinyHunters
organisation DMV
organisation DoppelCart
organisation IP
organisation safely.jpg
organisation EU CRA
organisation Perez-Etchegoyen
infrastructure 10,000 unique facing IP addresses
organisation The Blue Report 2026
organisation CTI
organisation Upcoming Webinar
organisation ClickFix
organisation Freestar.com
Tactical Metrics
Metrics
financial
3,798,315
Note Improper Control Vulnerability
Metrics
financial
3,781,729
Security Note
Metrics
infrastructure
‎Microsoft 365
Affected Product
Metrics
victims
258
Organizations
Metrics
infrastructure
‎Windows
Affected Product
Metrics
infrastructure
2,016
Windows Server
Metrics
infrastructure
‎Linux
Affected Product
Metrics
data_breach
0
September
Metrics
infrastructure
10,000
Unique Facing Ip Addresses
Metrics
financial
36,000,000,000
Revenues
Intelligence Sources
Infosecurity-Magazine 2026-09-09
BleepingComputer 2026-09-08