← Back

Wire · regulatory

SAP vulnerability “OVERPASS” may be its worst ever

Published

8 September 2026

Topic

regulatory

Sectors

CybersecurityEnterprise Software

Source

Read at thestack.technology

Verified

Fusion42 · 8 September 2026 · Fusion42 review

A critical SAP vulnerability named OVERPASS (CVE-2026-44756) affects most SAP business software, can be exploited remotely without authentication, and impacts over 10,000 publicly exposed customers. SAP has released a patch, but applying it is complex due to required system downtime; additional critical vulnerabilities were also disclosed.

This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.

◆ The Wire takeaway

You must prioritise rapid patching and downtime planning for SAP systems as pervasive vulnerabilities bypass all user controls. The vulnerability opens an urgent window for attackers that will soon be exploited broadly.

Coverage

1 source · 8 Sep 2026

Related on Wire

Topics

CybersecurityEnterprise Softwaresapsecurity-vulnerabilityenterprise-softwarepatchingcybersecurityerp