ALERTĂ: Vulnerabilități critice identificate la nivelul unor produse SAP
REZUMAT În data de 8 septembrie 2026, compania SAP a publicat actualizările de securitate af...
SAP RO
REZUMAT În data de 8 septembrie 2026, compania SAP a publicat actualizările de securitate af...
SAP RO
Sårbarhet Patchtisdag Cisco Microsoft SAP Ivanti Adobe
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication…
EPSS 0.00 CVSS 10.0 CVE-2026-44756 CVE-2026-58240 SAP EU
SAP heeft kwetsbaarheden verholpen in SAP Extended Passport Protocol (EPP) processing library, SAP NetWeaver Message Server, @sap/cds-mtxs NPM library, SAP GUI for Java, SAP ABAP Development Tools voor SAP NetWeaver AS ABAP, SAP Integration Suite, SAP NetWeaver Business Client, SAP Web Dispatcher, Internet Communication Manager, SAP Content Server, SAP S/4HANA Intercompany Matching and Reconciliation module, en SAP Manufacturing Integration and Intelligence. De kwetsbaarheid met kenmerk CVE…
EPSS 0.00 CVE-2026-44756 CVE-2026-58240 CVE-2026-66768 CVE-2026-76969 SAP NL
Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 10.0, CVEs: CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768, CVE-2026-58243, CVE-2026-76958, CVE-2026-76967, CVE-2026-66767, CVE-2026-2332, CVE-2026-76968, CVE-2026-44766, CVE-2026-76971, CVE-2026-34477, CVE-2026-76977, CVE-2026-76960, CVE-2026-76961, CVE-2026-76959, CVE-2026-76962, CVE-2026-76963, CVE-2026-58234, Summary: On 8th of September 2026, SAP security patch day saw the release of…
CVSS 10.0 SAP FI
Serial Number: AV26-894Date: September 8, 2026 As of September 8, 2026, SAP_SE is affected by vulnerabilities in the following products: SAP Extended Passport (EPP) Processing – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 SAP NetWeaver (Message Server) - versions KERNEL 9.16, 9.18, 9.19, and 9.20 SAP Cloud Application Programming Model (CAP) prior or equal to 1.183 prior…
SAP CA
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
EPSS 0.02 CVE-2026-44756 CVE-2026-58231 CVE-2026-58240 SAP US
Nell’ambito del Security Patch Day di settembre, SAP rilascia aggiornamenti di sicurezza per risolvere molteplici nuove vulnerabilità, di cui 4 con gravità “critica” e 4 con gravità “alta”.
EPSS 0.01 CVE-2026-2332 CVE-2026-44756 CVE-2026-58240 CVE-2026-66767 CVE-2026-66768 CVE-2026-76958 CVE-2026-76967 CVE-2026-76969 SAP IT
De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
SAP FR
Serial Number: AV26-798Date: August 11, 2026Updated: August 17, 2026 As of August 11, 2026, SAP is affected by vulnerabilities in the following products: SAP Commerce Cloud (Data Hub Adapter) Versions COM_CLOUD 2211 and 2211-JDK21 SAP Manufacturing Integration and Intelligence Versions XMII 15.4, 15.5, MII_ADMIN 15.4 and 15.5 SAP NetWeaver and ABAP Platform Versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7…
EPSS 0.02 CVE-2026-58231 SAP CA
SAP heeft een kwetsbaarheid verholpen in de Data Hub Adapter voor SAP Commerce Cloud. Een ongeauthenticeerde kwaadwillende kan de kwetsbaarheid misbruiken voor het uitvoeren van willekeurige code. Hiertoe dient de kwaadwillende malafide netwerkverkeer naar de Data Hub Adapter te versturen. Beveiligingsbedrijf Defused meldt dat kwaadwillenden actief scannen en op zoek zijn naar kwetsbare Data Hub Adapter-systemen.
SAP NL
Nell’ambito del Security Patch Day di agosto, SAP rilascia aggiornamenti di sicurezza per risolvere molteplici nuove vulnerabilità, di cui 2 con gravità “critica” e 6 con gravità “alta”.
EPSS 0.02 CVE-2026-34265 CVE-2026-44758 CVE-2026-44763 CVE-2026-44764 CVE-2026-44765 CVE-2026-44772 CVE-2026-58230 CVE-2026-58231 CVE-2026-58243 CVE-2026-66763 SAP IT
Flera leverantörer har släppt sina månatliga säkerhetsuppdateringar för juli. Nedan finns en sammanställning av de säkerhetsuppdateringar som Cisco, Microsoft, SAP, Ivanti, Fortinet och Adobe har publicerat inför och i samband med patchtisdagen. Följ länkarna för att komma till respektive leverantörs uppdateringar. [1, 2, 3, 4, 5, 6]
Compromised SAP npm packages use a Bun-based preinstall payload to steal GitHub, npm, cloud, and CI secrets, then spread via GitHub using OhNoWhatsGoingOnWithGitHub. Category: Vulnerabilities & Threats
SAP BE
Malicious versions of legitimate SAP ecosystem packages (e.g., @cap-js/sqlite, @cap-js/postgres) were created by modifying them to include a preinstall script that executes setup.mjs automatically during npm install. This script downloads the Bun runtime and executes an obfusc...
SAP US