# 2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

Publisher-attributed story with a reviewed brief or permitted publisher paragraph. The original publisher is responsible for the linked reporting.

- Publisher: CERT-EU
- Category: Vulnerabilities
- Original publication time: 2026-09-09T13:07:59Z
- First observed by NexusTechWire: 2026-10-01T17:27:53Z
- Original source: https://cert.europa.eu/publications/security-advisories/2026-011/
- NexusTechWire record: https://nexustechwire.com/news/news-51e05f44e8c37f44cc1a

## From the publisher

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products\[3\]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it\[3\]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server\[6\]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds\[6\].

Source license: [CC BY 4.0](https://creativecommons.org/licenses/by/4.0/). Publisher excerpt shortened and converted to plain text. Original source license applies.

Read the full original: [CERT-EU](https://cert.europa.eu/publications/security-advisories/2026-011/)

This record does not reproduce the complete article or represent independent confirmation of every source claim.
