SAP has issued an urgent security update for a maximum-severity vulnerability in SAP Extended Passport (EPP) processing, raising serious concerns for enterprises running business-critical SAP environments. Tracked as CVE-2026-44756, the vulnerability carries the highest possible CVSS score of 10.0.
Dubbed “OVERPASS” by researchers at Onapsis, the vulnerability involves memory corruption within SAP kernel code responsible for processing Extended Passport data. The flaw results from insufficient boundary validation while externally supplied EPP information is being processed.
The risk is particularly severe because exploitation can occur remotely without authentication. A specially crafted request could allow an attacker to compromise the receiving SAP process and potentially execute operating-system commands with SAP administrative privileges.
Successful exploitation could expose far more than one application. Researchers warn attackers could potentially access database credentials, password hashes, business information and active user-session data, alter configurations and application data, and use stored credentials for lateral movement across connected SAP environments.
Adding to the urgency, SAP also patched CVE-2026-58240, a critical missing-authentication vulnerability in the SAP NetWeaver Message Server carrying a CVSS score of 9.8. SAP’s September Patch Day included 19 new security notes and one update to a previously released note.
The vulnerabilities matter because SAP systems frequently sit at the heart of finance, manufacturing, supply chains, HR and enterprise operations. Compromising the underlying SAP environment can therefore translate directly into operational disruption, data theft and business risk.
SAP strongly recommends customers prioritize the relevant security patches. Organizations should immediately inventory affected SAP systems, prioritize internet-facing instances, reduce unnecessary exposure and monitor for suspicious activity.
The message for enterprises is clear: when a vulnerability scores a perfect 10 and requires no credentials, patching is no longer routine maintenance—it becomes a business-critical security response.
See What’s Next in Tech With the Fast Forward Newsletter
Tweets From @varindiamag
Nothing to see here - yet
When they Tweet, their Tweets will show up here.




