← Back to Feed

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

September 8, 2026 · BleepingComputer · Severity: HIGH

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security update, including a maximum-severity kernel vulnerability that could allow unauthenticated remote code execution. The critical flaw, rated CVSS 10.0, affects the SAP kernel component and requires immediate patching.

Key Takeaways

  • SAP's September 2026 security updates address a maximum-severity memory corruption vulnerability in the SAP Kernel known as OVERPASS.
  • The OVERPASS kernel vulnerability could allow an attacker to compromise the affected system without requiring prior authentication or user interaction.
  • Organizations running affected SAP systems must urgently apply the latest security patches to prevent exploitation of this critical memory corruption flaw.
☕ Buy a Coffee