SAP’s September 2026 Patch Day brings 22 new and updated Security Notes — including a maximum-severity, unauthenticated remote-compromise flaw in the SAP Kernel that researchers named OVERPASS.

SAP has released its September 2026 round of monthly security patches, addressing 22 new and updated Security Notes — five of them rated HotNews, the vendor’s highest severity tier, and six rated High Priority. Chief among them is a maximum-severity flaw in the SAP Kernel that the Onapsis Research Labs, which co-developed the fix with SAP, has named OVERPASS.

SAP’s September 2026 Security Patch Day landed with an unusually heavy critical load, headlined by a maximum-severity vulnerability in the SAP Kernel that could let an unauthenticated attacker take over affected systems remotely. The vendor published 22 new and updated Security Notes, including five HotNews Notes — SAP’s top severity classification — and six rated High Priority.

Six of the notes were developed jointly with the Onapsis Research Labs (ORL), the threat-research arm of SAP security vendor Onapsis, whose researchers said they helped SAP close eight distinct vulnerabilities across those six notes, three of which carry the HotNews label.

The most urgent of the batch is SAP Security Note #3747649, which carries the maximum CVSS score of 10.0 and fixes a memory-corruption flaw in SAP Extended Passport (EPP) Processing. Onapsis researchers, who named the vulnerability OVERPASS, traced the flaw to missing boundary checks during deserialization of EPP data: when the system processes an externally supplied length field, it can trigger a memory-safety violation. An attacker with no credentials could exploit this remotely by sending a malformed EPP header, potentially crashing affected processes or executing arbitrary operating-system commands with SAP’s own administrative privileges — effectively a full system compromise. SAP has issued patches for the ABAP and Java kernels and for SAP Web Dispatcher version 9.16; other Web Dispatcher builds, including the one bundled with SAP HANA Extended Application Services, are not affected. Onapsis is urging customers to patch immediately, noting the flaw is reachable through multiple SAP components and protocols, none of which require authentication, so no single network-level control can fully contain the risk.

A second maximum-severity note, #3771065, updates a fix first issued in August for an improper-authorization vulnerability in the SAP Commerce Cloud Data Hub Adapter. The revised note clarifies that unmodified Commerce Cloud environments are not exposed by default and points customers to an accompanying FAQ to verify their configuration.

The third HotNews entry co-developed with Onapsis, Note #3759472 (CVSS 9.8), addresses a flaw the researchers call S4GET — a weakness in the SAP NetWeaver Message Server that fails to properly verify the identity of internal application-server components during registration. Because the message server sits at the center of how SAP’s kernel processes communicate, an unauthenticated attacker with network access could register rogue components and carry out unauthorized actions inside the environment. Onapsis said the affected kernel versions, 9.16 through 9.20, span SAP’s entire current kernel family, meaning every SAP S/4HANA 2025 system, along with any earlier release already migrated to one of those kernels, is exposed.

Rounding out the HotNews group are Note #3798315 (CVSS 9.4), a credential-disclosure flaw in a third-party NPM library used by multitenant applications built on the SAP Cloud Application Programming Model, and Note #3781729 (CVSS 9.0), which fixes a trust-policy enforcement gap in SAP GUI for Java that could let a low-privileged user trigger arbitrary command execution on a victim’s machine through a manipulated backend connection. For the credential-disclosure flaw, SAP Cloud Foundry customers running unpatched applications will temporarily lose the ability to modify tenant-level extensions; a workaround for customers outside Cloud Foundry is detailed in a separate FAQ note.

Among the six High Priority notes, an XML External Entity vulnerability in SAP Integration Suite (#3792978, CVSS 8.5) stands out for its operational impact: patched iFlow packages disable external entity resolution outright, which Onapsis warned could break integration scenarios that intentionally rely on that functionality. Other High Priority fixes touch SAP NetWeaver Business Client, SAP NetWeaver Application Server for ABAP, a third-party denial-of-service flaw affecting S/4HANA’s Manage Supply Protection function, and a request-smuggling issue in SAP Commerce Cloud tied to the underlying Jetty component.

Onapsis’s own contribution extended beyond the HotNews tier: the firm said it also worked with SAP on three Medium Priority notes, all carrying a CVSS score of 6.5, covering an SQL-injection flaw in S/4HANA’s Intercompany Matching and Reconciliation module, a server-side request forgery issue in SAP Manufacturing Integration and Intelligence, and an information-disclosure weakness spanning SAP Web Dispatcher, the Internet Communication Manager and SAP Content Server.

SAP and Onapsis are hosting a joint threat briefing webinar on September 9 at 10 a.m. EDT to walk customers through the OVERPASS vulnerability and the rest of the month’s critical fixes. Onapsis said it is already updating its own platform to reflect the newly disclosed issues, and it recommends organizations prioritize patching by exploitability, starting with OVERPASS, given it requires no authentication and can be triggered through multiple network paths.

By Jakob Jung

Dr. Jakob Jung is Editor-in-Chief of Security Storage and Channel Germany. He has been working in IT journalism for more than 20 years. His career includes Computer Reseller News, Heise Resale, Informationweek, Techtarget (storage and data center) and ChannelBiz. He also freelances for numerous IT publications, including Computerwoche, Channelpartner, IT-Business, Storage-Insider and ZDnet. His main topics are channel, storage, security, data center, ERP and CRM. Contact via Mail: jakob.jung@security-storage-und-channel-germany.de

One thought on “SAP Patches Maximum-Severity “OVERPASS” Kernel Flaw in September Security Update”

Leave a Reply

Your email address will not be published. Required fields are marked *

WordPress Cookie Notice by Real Cookie Banner