SAP has released a series of security updates, including a crucial patch for a serious memory corruption vulnerability identified as CVE-2026-44756. This issue, known as OVERPASS, affects the Extended Passport Processing (EPP) in SAP’s kernel. The flaw allows unauthenticated attackers to execute arbitrary commands, recover sensitive data, and modify critical system configurations. According to Onapsis, a firm specializing in application security, the vulnerability is present in various SAP components, impacting products such as S/4HANA, ERP, and NetWeaver. The vulnerability occurs during the deserialization of EPP data, leading to unsafe memory behavior when processing external inputs.

The defect can be triggered as soon as a user session opens, bypassing multiple security controls like user roles and authorization policies. This makes the vulnerability particularly worrying, as it can be exploited via multiple vectors, including web requests and the SAP GUI protocol. The severity of the flaw is underscored by the fact that affected components operate under the main SAP system account, granting attackers extensive control over the system.

While there are no reports of this vulnerability being exploited in the wild, its potential impact is significant. Additionally, SAP has addressed three other critical vulnerabilities, including CVE-2026-58240, CVE-2026-76969, and CVE-2026-66768, which involve missing authentication checks and improper access controls. SAP's latest security notes also cover high-severity issues in ABAP Developer Tools, Integration Suite, and other components. This highlights the importance of staying vigilant and promptly applying security patches to protect against potential threats.