← Back to Feed
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
September 8, 2026 · BleepingComputer · Severity: HIGH
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security update, including a maximum-severity kernel vulnerability that could allow unauthenticated remote code execution. The critical flaw, rated CVSS 10.0, affects the SAP kernel component and requires immediate patching.
Key Takeaways
- SAP's September 2026 security updates address a maximum-severity memory corruption vulnerability in the SAP Kernel known as OVERPASS.
- The OVERPASS kernel vulnerability could allow an attacker to compromise the affected system without requiring prior authentication or user interaction.
- Organizations running affected SAP systems must urgently apply the latest security patches to prevent exploitation of this critical memory corruption flaw.