FR
live
tag

#s4get

SAP patches OVERPASS and S4GET, two pre-auth flaws that run code on the SAP kernel

On September 9, 2026, SAP shipped fixes for four critical flaws, including CVE-2026-44756 (CVSS 10.0), a memory-corruption bug in Extended Passport processing that yields unauthenticated remote code execution across three protocols at once. Basis teams should patch the SAP kernel first, ahead of any network segmentation effort.

Type at least two characters.

navigate open esc dismiss