security1 publisher
Unauthenticated SAP attackers hit memory corruption before any login check
Onapsis found CVE-2026-44756 in SAP's Extended Passport code, Pathlock and nullFaktor reproduced remote code execution in a lab, and technical write-ups went public within 48 hours of the patch. Mandiant's AI report is the week's other substance.
Publishers:securityweek.com
Reality
- Evidence58
- Adoption45
- Hype gap+10
- Incentives68
- Confidence50