SAP’s September 8 Security Patch Day led with Note 3747649 for CVE-2026-44756 — a Critical / CVSS 10.0 memory-corruption flaw in SAP Extended Passport (EPP) processing inside shared kernel code. Onapsis Research Labs, which disclosed it as OVERPASS, says the defect is reachable before authentication over the web tier (ICM / Web Dispatcher), the SAP GUI dispatcher every end user needs, and RFC links between systems. Successful exploitation yields OS command execution as the SAP administrative host account — credentials, live sessions, binaries, and connected trusts included.
Affected footprints listed on SAP’s Patch Day note include KERNEL and KRNL64 builds across 7.22 through 9.20 and WEBDISP 9.16–9.20, which underpins S/4HANA, ECC / Business Suite, NetWeaver AS ABAP, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager, and peers. Onapsis estimates more than 10,000 unique internet-facing IP addresses presenting an SAP web interface — called conservative because Web Dispatcher backends often lack a distinguishing banner. As of Onapsis’ September 9 update, researchers report no observed in-the-wild exploitation; SAP’s public note likewise does not claim active abuse.
Same Patch Day also shipped Note 3759472 for CVE-2026-58240 (S4GET) — a Critical / CVSS 9.8 missing-authentication check in the NetWeaver Message Server on modern KERNEL 9.16–9.20 — plus two more Critical notes (CAP credential disclosure CVE-2026-76969, GUI-for-Java access control CVE-2026-66768). For OVERPASS, Onapsis says a single kernel patch closes every described vector; authorizations and SoD do not help because EPP runs before logon controls. FAQ Note 3776034 and HTTP workaround Note 3756304 are secondary — patch is the underwrite.
The sourced facts: CVSS 10 unauth kernel RCE, Note 3747649 HotNews, Onapsis OVERPASS / >10k internet-facing estimate, no confirmed in-wild exploitation yet, companion Critical Message Server note 3759472. Victim count: Undisclosed. Inventory kernels against 3747649, internet-facing first, then every system whose SAP GUI or RFC path is reachable.
