Wire · regulatory
SAP Patches Maximum Severity “Overpass” Flaw
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 9 September 2026 · Fusion42 review
Onapsis Research Labs discovered and responsibly disclosed a critical memory corruption vulnerability in the SAP kernel termed CVE-2026-44756, which affects over 10,000 internet-facing SAP systems and allows unauthenticated remote code execution with administrative privileges. Additional critical vulnerabilities in SAP S/4HANA, SAP Cloud Application Programming Model, and SAP NetWeaver also require urgent patching to prevent full system compromise.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.
◆ ◆ The Wire takeaway
You must prioritise patching SAP systems immediately to avoid catastrophic remote takeover risks that can cripple your business operations. Attackers can exploit this now unprotected access vector to run commands with full admin rights, making delay fatal.
◆ Coverage
1 source · 9 Sep 2026
◆ Related on Wire
◆ Topics