SAP patches critical flaw rated 10/10, SecurityWeek reports
SecurityWeek says the flaw affects SAP kernel code and allows remote attackers without authentication to run arbitrary commands, recover secrets and modify data.
TLDR
SecurityWeek reports that SAP released 20 new and updated security notes on September 8, including a fix for CVE-2026-44756. The publisher describes it as a critical memory corruption vulnerability in Extended Passport processing, with a CVSS severity score of 10/10. It says the flaw affects SAP kernel code and allows unauthenticated remote attackers to run arbitrary commands, recover secrets and modify data.
Combined views
2.9K
1 Source, first seen ago