Onapsis found CVE-2026-44756 in SAP's Extended Passport code, Pathlock and nullFaktor reproduced remote code execution in a lab, and technical write-ups went public within 48 hours of the patch. Mandiant's AI report is the week's other substance.
Reality
- Evidence58
- Adoption45
- Hype gap+10
- Incentives68
- Confidence50
SAP shipped Security Note 3747649 on September 8 for CVE-2026-44756, a memory corruption bug in Extended Passport processing that Onapsis says gives unauthenticated callers command execution as the account owning the SAP install.
Publishers:securityweek.com · socprime.com Reality
- Evidence72
- Adoption24
- Hype gap+14
- Incentives68
- Confidence66
Ivan Mans of SecurityBridge says the SAP security question is now what an agent already inside the system is allowed to do and whether anyone can prove it afterward. His incident record comes from developer tooling.
Reality
- Evidence33
- Adoption28
- Hype gap+38
- Incentives84
- Confidence64
Onapsis says the OVERPASS overflow fires while the SAP kernel processes an Extended Passport at session initiation, which happens before authentication or logon policy is consulted. That leaves reachability and patch state as the only variables.
Reality
- Evidence47
- Adoption
- Insufficient
- Hype gap+9
- Incentives62
- Confidence43
CVE-2026-58231 chains a default auth client with missing input validation in SAP's Data Hub Adapter. The fix needs a rebuild and redeploy; the attackers needed 72 hours.
Reality
- Evidence42
- Adoption28
- Hype gap+12
- Incentives38
- Confidence44