A newly disclosed vulnerability lets attackers with only network access seize full control of SAP application servers — no login required. Researchers warn the flaw’s reachability makes it harder to contain than the notorious 2019 10KBLAZE exploit.
SAP has released an emergency fix for a critical vulnerability in its NetWeaver Message Server that allows unauthenticated attackers to gain remote code execution on affected systems, according to a joint threat advisory published by SAP and cybersecurity firm Onapsis on September 8, 2026.
The flaw, tracked as CVE-2026-58240 and dubbed S4GET, carries a CVSS score of 9.8, the near-maximum severity rating. Onapsis, which discovered the issue through its ongoing coordinated-disclosure partnership with SAP, describes S4GET as a logic flaw rather than a misconfiguration, present in SAP’s 9.x kernel lines that underpin SAP S/4HANA, SAP S/4HANA Cloud Private Edition, and other ABAP-based products. A fix is available in SAP Security Note 3759472.
What makes the vulnerability notable, according to Onapsis, is its reachability. The flaw is triggered through the same public port every SAP GUI client uses to connect, meaning it cannot simply be blocked at the firewall without breaking normal user logins. Exploitation requires no credentials, no certificate, and no prior misconfiguration.
Onapsis researchers explain that the SAP Message Server acts as a broker, tracking which application servers are active and routing logon requests. A separate component, the SAP Gateway, decides which hosts to treat as trusted based on information supplied by the Message Server. By sending a crafted packet to the Message Server’s public port, an attacker can have an arbitrary IP address treated as trusted across the cluster. That IP can then connect to the Gateway, invoke RFC-callable external programs, and obtain remote code execution as sid-adm, the operating-system account that runs SAP, on every affected application server.
Standard SAP access-control lists, including secinfo, reginfo, and ms/acl_info, do not sit in this attack path, according to the advisory, meaning properly configured systems remain exposed.
Onapsis draws a direct comparison to 10KBLAZE, a set of SAP vulnerabilities disclosed in 2019 that abused a permissive access-control list on the Message Server’s internal port. Where 10KBLAZE stemmed from a misconfiguration on a port not meant to be exposed, S4GET is a vulnerability reachable through the Message Server’s public-facing port, which the company says is routinely open on corporate networks to support everyday SAP GUI logons.
Direct exposure of the Message Server to the public internet is rare, Onapsis said, but reachability inside a corporate network is the norm rather than the exception. Any attacker with a foothold on the internal network, for instance through a phished workstation or a compromised VPN session, would be positioned to exploit the flaw. A successful attack could lead to ransomware deployment, data destruction, exfiltration of business records, or fraudulent transactions, with potential compliance implications under regulations including GDPR, NIS2, and SOX, the companies said.
The disclosure follows a pattern security researchers have flagged before. Onapsis pointed to CVE-2025-31324, an unauthenticated file-upload flaw in a separate NetWeaver component that was exploited in the wild before many organizations could patch it, and which Mandiant’s 2026 M-Trends report named the most exploited vulnerability of that year. Onapsis also noted that attackers have historically reverse-engineered SAP patches within roughly 72 hours of release, a timeline the company says continues to shrink with the use of AI-assisted tooling.
To assess exposure, SAP and Onapsis recommend organizations check their kernel release and patch level rather than relying on which SAP product they run, since the affected kernel lines can appear across multiple product releases through upgrades. According to SAP Security Note 3759472, systems are vulnerable if running kernel 9.16 below patch level 100, kernel 9.18 below patch level 32, kernel 9.19 below patch level 17, or kernel 9.20 below patch level 7. The kernel version can be checked through SAP GUI under System, Status, Kernel Information, or at the operating-system level using the disp+work -version command.
SAP and Onapsis advise a phased remediation approach: inventory all systems running an affected kernel and patch level, prioritize any systems with direct internet exposure to the Message Server’s public port, then work through internally reachable systems, which the companies expect to represent the bulk of affected estates. Organizations unable to patch immediately are advised to monitor for exploitation attempts as a compensating control.
Onapsis said it has not observed active exploitation of S4GET in the wild as of publication, and that its Global Threat Intelligence Network continues to monitor for signs of malicious activity. The company said its Defend product had been monitoring customer environments for the vulnerability pattern since before the patch was released, under the terms of the coordinated-disclosure agreement, and that its Assess product has been updated to help customers identify which systems in their estate are exposed.
SAP and Onapsis held a joint threat briefing webinar on the vulnerability on September 9, 2026.

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM.
Contact via Mail: jakob.jung@security-storage-und-channel-germany.de