Wire · regulatory
SAP vulnerability “OVERPASS” may be its worst ever
◆ Sectors
◆ Source
◆ Verified
Fusion42 · 8 September 2026 · Fusion42 review
A critical SAP vulnerability named OVERPASS (CVE-2026-44756) affects most SAP business software, can be exploited remotely without authentication, and impacts over 10,000 publicly exposed customers. SAP has released a patch, but applying it is complex due to required system downtime; additional critical vulnerabilities were also disclosed.
This Wire brief sits within Fusion42's coverage of Cybersecurity and Enterprise Software.
◆ ◆ The Wire takeaway
You must prioritise rapid patching and downtime planning for SAP systems as pervasive vulnerabilities bypass all user controls. The vulnerability opens an urgent window for attackers that will soon be exploited broadly.
◆ Coverage
1 source · 8 Sep 2026
◆ Related on Wire
◆ Topics