← Back

Wire · regulatory

SAP Patches Maximum Severity “Overpass” Flaw

Published

9 September 2026

Topic

regulatory

Sectors

CybersecurityEnterprise Software

Source

Read at infosecurity-magazine.com

Verified

Fusion42 · 9 September 2026 · Fusion42 review

Onapsis Research Labs discovered and responsibly disclosed a critical memory corruption vulnerability in the SAP kernel termed CVE-2026-44756, which affects over 10,000 internet-facing SAP systems and allows unauthenticated remote code execution with administrative privileges. Additional critical vulnerabilities in SAP S/4HANA, SAP Cloud Application Programming Model, and SAP NetWeaver also require urgent patching to prevent full system compromise.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.

◆ The Wire takeaway

You must prioritise patching SAP systems immediately to avoid catastrophic remote takeover risks that can cripple your business operations. Attackers can exploit this now unprotected access vector to run commands with full admin rights, making delay fatal.

Coverage

1 source · 9 Sep 2026

Related on Wire

Topics

CybersecurityEnterprise Softwaresapvulnerabilitycritical-patchsecurityremote-execution