SAP patches CVSS 10 OVERPASS flaw in Extended Passport
SAP Security Note 3747649 (CVE-2026-44756) patches a CVSS 10.0 memory corruption bug in Extended Passport processing on listed KERNEL, WEBDISP, and KRNL64 builds. Onapsis, which named the bug OVERPASS, says the path fires as the session opens, before authorization.

SAP's September 2026 Security Patch Day, posted 8 September, leads with Security Note 3747649. The note assigns CVE-2026-44756, rates it Critical at CVSS 10.0, and describes a memory corruption vulnerability in SAP Extended Passport (EPP) Processing. The Patch Day tally is 19 new notes and 1 update.
This is a vendor Security Note on SAP Patch Day. OVERPASS is the name Onapsis gave the bug. It is not SAP's official name, and it is not a CISA Known Exploited Vulnerabilities listing.
SAP's affected-version table covers KRNL64NUC 7.22 and 7.22EXT; KRNL64UC 7.22, 7.22EXT, 7.53, and 8.04; WEBDISP 9.16, 9.18, 9.19, and 9.20; and KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, and 9.20.
Onapsis's OVERPASS remediation note says boundary validation is missing when the kernel deserializes attacker-supplied EPP length fields. The path is unauthenticated and remote, over web (Internet Communication Manager and Web Dispatcher), the SAP GUI protocol, and RFC. It triggers as the session opens, before user locks, roles, and authorization objects apply.
SecurityWeek repeats that path. Onapsis says a successful run can execute operating-system commands under the SAP install owner, recover credentials and hashes, read live sessions, and change configuration or binaries.
Onapsis has not observed in-the-wild exploitation at publication. The 10,000-plus internet-facing SAP web interfaces Onapsis counted are a researcher estimate, not an SAP figure. Public diffs usually follow a kernel patch. FAQ note 3776034 and HTTP workaround note 3756304 sit next to the main note.
Kernel and pre-auth remote access this week also includes ConnectWise's ScreenConnect file transfer advisory, PostgreSQL logical-decoding CVE-2026-6471, N-able N-central CVE-2026-86218, and Telerik's public upload RCE exploit.
If you run SAP ABAP or Java kernels or Web Dispatcher on the listed builds, treat Note 3747649 as emergency patching before public diffs land, and verify WEBDISP 9.16 and later paths Onapsis called out.
Cyberpresso: daily cyber & AI brief
Free daily newsletter, read in 5 minutes.
Subscribe free