SAP issues emergency kernel patches for critical flaws
🛡️ Onapsis has disclosed a maximum severity memory corruption vulnerability in the SAP kernel, tracked as CVE-2026-44756, which may affect over 10,000 internet-facing SAP systems. The bug exists in SAP Extended Passport (EPP) Processing and can be triggered remotely without authentication via crafted network requests, potentially allowing attackers to execute arbitrary OS commands with SAP admin privileges. Onapsis also warned of several other critical issues, including S4GET (CVE-2026-58240) and additional high-severity flaws, and urged customers to apply SAP security notes immediately.
