SAP Patches Critical 'OVERPASS' and 'S4GET' Vulnerabilities Exposing Thousands of Systems
**SAP** has released its September 2026 security updates, addressing 20 vulnerabilities across various products. Among these are two maximum-severity flaws, dubbed **OVERPASS** and **S4GET** by security researchers, that could allow unauthenticated attackers to gain administrative privileges and execute arbitrary commands on thousands of internet-facing SAP systems.
## Maximum-Severity Flaws in SAP Kernel and NetWeaver Message Server
**SAP** has patched a critical memory corruption vulnerability, **CVE-2026-44756**, in its Kernel code. Tracked as **OVERPASS** by **Onapsis** security researchers who reported it, this flaw is a classic buffer overflow weakness within the Extended Passport Protocol (EPP) processing library.
Successful exploitation of **OVERPASS** allows unprivileged threat actors to execute arbitrary commands on vulnerable SAP hosts with administrative privileges. This can lead to a full compromise of underlying SAP processes and sensitive business data. The vulnerability can be exploited over **SAP Internet Communication Manager (ICM)**, the networking component connecting the SAP System to the internet via HTTP, HTTPS, and SMTP.
**Onapsis** estimates that over 10,000 internet-facing SAP systems utilize the vulnerable component, potentially exposing them to attacks. **JP Perez-Etchegoyen**, CTO at **Onapsis**, noted that this figure is conservative, primarily counting HTTP-reachable systems and undercounting **SAP Web Dispatcher** instances.
## S4GET: Unauthenticated Access to SAP Clusters
**SAP** also addressed **CVE-2026-58240**, a critical missing authentication vulnerability in the **SAP NetWeaver Message Server**, dubbed **S4GET** by **Onapsis Research Labs**.
Exploitation of **S4GET** allows unauthenticated attackers to access the entire SAP system cluster, executing malicious payloads and arbitrary commands remotely across the network. **Pablo Artuso**, an **Onapsis** security researcher, highlighted that the flaw is triggered through the same public port used by every **SAP GUI** client, making it difficult to firewall without disrupting end-user logins.
βExploitation requires no credentials, no certificate, and no pre-existing misconfiguration. A successful attack yields full remote code execution as `<sid>adm`, the OS-level user that runs SAP, on every application server in the cluster,β Artuso explained.
## Ongoing Threat Landscape for SAP Systems
These patches follow a recent maximum-severity vulnerability, **CVE-2026-58231**, in **SAP Commerce Cloud**, which was actively exploited in attacks shortly after being patched last month. The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has added 14 SAP security flaws to its list of actively exploited vulnerabilities since November 2021, with three of these being leveraged by ransomware gangs.
**SAP**, a German multinational software company, reported revenues exceeding β¬36 billion in fiscal year 2025 and provides services to 99 of the 100 largest companies worldwide, underscoring the critical importance of these security updates for global enterprises.