# Critical SAP Vulnerabilities Demand Immediate Action

*Published September 11, 2026*
*Source: [https://www.infosecurity-magazine.com/news/sap-patches-maximum-severity/](https://www.infosecurity-magazine.com/news/sap-patches-maximum-severity/)*

## Executive Summary

*This is a Premium edition. The Executive Summary is available to sec-news.ai members —*
*[read it here](https://www.sec-news.ai/news/critical-sap-vulnerabilities-demand-immediate-action) or [see plans](https://www.sec-news.ai/pricing).*

## Article

Over 10,000 SAP systems exposed to the internet may be at risk due to a critical vulnerability identified in the SAP kernel. Security firm Onapsis has highlighted this issue, which stems from a Memory Corruption vulnerability in SAP Extended Passport Processing, known as CVE-2026-44756. Onapsis Research Labs was responsible for discovering and disclosing this flaw to SAP.

The vulnerability arises because of a lack of boundary validation during the deserialization of Extended Passport Processing data, leading to potential memory safety violations. This issue allows attackers without authentication to send specially crafted network requests with malformed headers, resulting in undefined behavior or program termination.

The vulnerability is particularly concerning because it can be accessed from both the SAP GUI layer, which every end user interacts with, and the RFC layer, connecting various SAP systems. As the flaw exists in default configurations, it is ripe for exploitation, enabling remote attackers to execute arbitrary OS commands with SAP administrative privileges, potentially compromising critical business data and processes.

Although no active exploitation has been reported yet, the potential impact underscores the urgency for SAP customers to apply patches immediately. In addition to CVE-2026-44756, another critical vulnerability, CVE-2026-58240, labeled 'S4GET', also demands attention. This flaw affects the Message Server in certain SAP S/4HANA versions, allowing attackers to execute malicious payloads and commands remotely.

SAP customers are strongly urged to prioritize patching these vulnerabilities to safeguard their systems from potential threats.
