Pandorex
Security

SAP Patch Day: CVSS 10 Flaw Hits Kernel and Web Dispatcher Without Authentication

Published Pandorex Redaktion·4 min read
—

Summary: SAP released 19 new Security Notes and one update for its September Patch Day. The highest-priority issue is CVE-2026-44756 at CVSS 10.0, a memory-corruption flaw in Extended Passport processing across SAP Kernel and Web Dispatcher. Its reach goes beyond one web component because the same kernel code is exposed through multiple SAP protocols.

SAP Security Note 3747649 covers numerous kernel release lines as well as Web Dispatcher 9.16 through 9.20. Onapsis, which reported the flaw to SAP, describes missing boundary validation while Extended Passport data is deserialized. Crafted length fields can trigger unsafe memory behavior. The CVSS vector requires network access but no previous privileges and no user interaction.

Why the exposure is unusually broad

Extended Passport is a tracing structure that can accompany SAP requests. According to Onapsis, the vulnerable processing sits in shared kernel code and is therefore reachable not only through the web layer but also through SAP GUI and RFC paths. Successful exploitation can reach arbitrary system-command execution. Active exploitation in the wild had not been confirmed at publication time.

The September release contains other critical issues. CVE-2026-58240 in the NetWeaver Message Server scores 9.8 and can allow an unauthenticated attacker with network access to register an unauthorized component. CVE-2026-76969 affects the Cloud Application Programming Model multitenancy library @sap/cds-mtxs and can disclose credentials.

Pandorex Analysis

The important connection is not the count of 19 new notes but where the flaws sit: the kernel, the Message Server and a core cloud multitenancy library are all deep platform components. Checking only internet-facing web endpoints is therefore insufficient for CVE-2026-44756 because internal SAP GUI and RFC paths can also matter.

Priority should start with version inventory against Notes 3747649 and 3759472. Network segmentation can reduce reachability, but for these unauthenticated attack paths it is not a substitute for patching.

Sources and references

Sources used for the facts and context in this article.

  1. SAP, 08.09.2026: SAP Security Patch Day - September 2026support.sap.com
  2. Onapsis, 08.09.2026: Remediating OVERPASS (CVE-2026-44756)onapsis.com
  3. Onapsis, 08.09.2026: SAP Security Patch Day for September 2026onapsis.com
  4. SecurityWeek, 08.09.2026: SAP Patches Critical Extended Passport Processing Vulnerabilitysecurityweek.com

How Pandorex researches and corrects articles

Comments

Sign in to write a comment.

Swipe up
Next Article

Exchange KB5121608 Fixes Eight CVEs — and Ships With Two Known Hybrid Issues

Security