Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

SAP Patches Critical Flaws in Extended Passport and NetWeaver, Potential for Unauthenticated Remote Code Execution


THN has reported on the critical security patches released by SAP to address multiple vulnerabilities in their systems. These patches address two severe vulnerabilities, CVE-2026-44756 and CVE-2026-58240, with a combined CVSS score of 10.0, indicating an extremely high level of risk. Organizations must take immediate action to patch these vulnerabilities and reduce their exposure to these threats.

  • The SAP system has released critical security patches to address multiple vulnerabilities with a Combined Vulnerability Severity Score (CVSS) of 10.0.
  • Two vulnerabilities stand out, CVE-2026-44756 (memory corruption) and CVE-2026-58240 (logic flaw), which can be exploited remotely without authentication.
  • The SAP kernel's processing of the Extended Passport (EPP) is affected by CVE-2026-44756, allowing an attacker to run arbitrary operating system commands.
  • The S4GET vulnerability (CVE-2026-58240) is present in SAP's 9.x kernel lines and can be exploited in other ABAP-based products.
  • The reachability of the S4GET vulnerability is concerning, as it can be triggered through a public port used by SAP GUI clients.
  • Exploitation of this vulnerability requires no credentials, no certificate, and no pre-existing misconfiguration, making it highly dangerous.
  • The impact of this vulnerability is severe, allowing an attacker to access sensitive business data and processes.
  • SAP has released security updates, and Onapsis advises users to take immediate action, including patching internet-facing systems and monitoring for exploitation attempts.
  • The vulnerability highlights the importance of staying vigilant in the face of emerging threats and requires organizations to take immediate action to patch these vulnerabilities.



  • Threat Intelligence Agency The Hacker News (THN) has recently reported on the critical security patches released by SAP to address multiple vulnerabilities in their systems. Among these vulnerabilities, two stand out as particularly severe, with a Combined Vulnerability Severity Score (CVSS) of 10.0, indicating an extremely high level of risk.

    The first vulnerability, CVE-2026-44756, has been categorized as a case of memory corruption. This flaw resides in the SAP kernel's processing of the Extended Passport (EPP), making it exploitable remotely and without authentication. This means that an attacker can run arbitrary operating system commands on the SAP host, leading to a complete compromise of the underlying SAP business data and processes.

    The second vulnerability, CVE-2026-58240, has been named S4GET and is a logic flaw, not a misconfiguration. This vulnerability is present in SAP's 9.x kernel lines, which are used by SAP S/4HANA and SAP S/4HANA Cloud Private Edition. It is also potentially exploitable in other ABAP-based products.

    Onapsis, the company that discovered and reported these vulnerabilities, notes that the reachability of this flaw is particularly concerning. The flaw is triggered through the same public port that every SAP GUI client connects to, meaning it cannot be firewalled away without breaking the end-user logon. Exploitation of this vulnerability requires no credentials, no certificate, and no pre-existing misconfiguration, making it highly dangerous.

    The impact of this vulnerability is severe, as it allows an attacker to read the SAP secure store to recover database credentials, password hashes and all housed business data; read the live session data of logged-in users; extract stored credentials to move laterally into every other SAP system; and modify application data, system configuration, and the SAP binaries.

    SAP has released security updates to address these vulnerabilities, and Onapsis is advising users to take immediate action. This includes patching internet-facing systems before internal instances, reducing exposure where possible, and monitoring for exploitation attempts.

    The importance of this vulnerability cannot be overstated. Onapsis has stated that "SAP authorizations and Segregation of Duties (SoD) controls will not help" in preventing the exploitation of this vulnerability. This means that even if an organization has robust security measures in place, it may not be enough to protect against this particular vulnerability.

    In conclusion, the recent security patches released by SAP highlight the importance of staying vigilant in the face of emerging threats. The vulnerabilities reported in this article are particularly severe, with the potential for unauthenticated remote code execution. Organizations must take immediate action to patch these vulnerabilities and reduce their exposure to these threats.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/SAP-Patches-Critical-Flaws-in-Extended-Passport-and-NetWeaver-Potential-for-Unauthenticated-Remote-Code-Execution-ehn.shtml

  • https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html

  • https://nvd.nist.gov/vuln/detail/CVE-2026-44756

  • https://www.cvedetails.com/cve/CVE-2026-44756/

  • https://nvd.nist.gov/vuln/detail/CVE-2026-58240

  • https://www.cvedetails.com/cve/CVE-2026-58240/


  • Published: Wed Sep 9 05:21:33 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us