← nejvýznamnější zprávy · všechny zprávy

SPOJENO AI EPSS 0.01 (nejvyšší)

2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication…

Číst originál na CERT-EU →

8 zpráv z 8 zdrojů · první 8. 9. 02:00 · poslední 11. 9. 10:55 CZ · EN/orig

SAP RO EU NL FI CA US IT FR

tg: zranitelnost tp: DDoS tp: identita

CVE v události 8

CVEhodnoceníKEVEPSS
CVE-2026-2332 7.4 3.1 · eclipse 7.4 3.1 · redhat-SADP 0.01
CVE-2026-44756 10.0 3.1 · sap 0.00
CVE-2026-58240 9.8 3.1 · sap 0.00
CVE-2026-66767 7.7 3.1 · sap 0.00
CVE-2026-66768 9.0 3.1 · sap 0.00
CVE-2026-76958 8.5 3.1 · sap 0.00
CVE-2026-76967 7.8 3.1 · sap 0.00
CVE-2026-76969 9.4 3.1 · sap 0.00

Hodnocení z katalogů, všechna, se stupnicí CVSS a vydavatelem. Rozpad vektoru je na stránce CVE. Advisory v textu uvádí CVSS 10.0.

Tohle CVE jsem vytáhl z širšího textu článku: CVE-2026-58231. Neukazuju u něj proto fakta z katalogů výše, a to preventivně, protože článek se na něj mohl jen odkazovat, třeba jako na starší kauzu.

Jak se o tom psalo 8

  1. · DNSC Rumunsko RO

    ALERTĂ: Vulnerabilități critice identificate la nivelul unor produse SAP

    REZUMAT În data de 8 septembrie 2026, compania SAP a publicat actualizările de securitate af...

  2. · CERT-EU EU nadpis události

    2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

    On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication…

  3. · NCSC-NL NL

    NCSC-2026-0356 [1.00] [M/H] Kwetsbaarheden verholpen in diverse SAP-producten

    SAP heeft kwetsbaarheden verholpen in SAP Extended Passport Protocol (EPP) processing library, SAP NetWeaver Message Server, @sap/cds-mtxs NPM library, SAP GUI for Java, SAP ABAP Development Tools voor SAP NetWeaver AS ABAP, SAP Integration Suite, SAP NetWeaver Business Client, SAP Web Dispatcher, Internet Communication Manager, SAP Content Server, SAP S/4HANA Intercompany Matching and Reconciliation module, en SAP Manufacturing Integration and Intelligence. De kwetsbaarheid met kenmerk CVE…

  4. · NCSC-FI FI

    SAP Security Patch Day - September 2026

    Classification: Critical, Solution: Official Fix, Exploit Maturity: Not Defined, CVSSv3.0: 10.0, CVEs: CVE-2026-44756, CVE-2026-58240, CVE-2026-76969, CVE-2026-66768, CVE-2026-58243, CVE-2026-76958, CVE-2026-76967, CVE-2026-66767, CVE-2026-2332, CVE-2026-76968, CVE-2026-44766, CVE-2026-76971, CVE-2026-34477, CVE-2026-76977, CVE-2026-76960, CVE-2026-76961, CVE-2026-76959, CVE-2026-76962, CVE-2026-76963, CVE-2026-58234, Summary: On 8th of September 2026, SAP security patch day saw the release of…

  5. · Cyber Centre Kanada CA

    SAP security advisory – September 2026 monthly rollup (AV26-894)

    Serial Number: AV26-894Date: September 8, 2026 As of September 8, 2026, SAP_SE is affected by vulnerabilities in the following products: SAP Extended Passport (EPP) Processing – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 SAP NetWeaver (Message Server) - versions KERNEL 9.16, 9.18, 9.19, and 9.20 SAP Cloud Application Programming Model (CAP) prior or equal to 1.183 prior…

  6. · BleepingComputer US

    SAP warns of maximum severity 'OVERPASS' kernel vulnerability

    SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]

  7. · CSIRT Itálie (ACN) IT

    SAP Security Patch Day

    Nell’ambito del Security Patch Day di settembre, SAP rilascia aggiornamenti di sicurezza per risolvere molteplici nuove vulnerabilità, di cui 4 con gravità “critica” e 4 con gravità “alta”.

  8. · CERT-FR – avis FR

    Multiples vulnérabilités dans les produits SAP (08 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.