CVE-2026-44756

Published Sep 8, 2026

Last updated 2 days ago

Overview

Description
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Source
cna@sap.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-120

Social media

Hype score
Not currently trending
  1. 🔒 #CyberSecurity CVE-2026-44756: SAP Kernel CVSS 10.0 Unauthenticated RCE — Detection and Remedi… "SAP's September 2026 Security Patch Day delivered what every enterprise defender dreads: a…" 🔗 https://t.co/kxluyDvDkv #CyberSecurity #ThreatIntel #critical #zeroday

    @SecurityAr58409

    9 Sept 2026

    30 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. News: SAP Patch Day: OVERPASS CVE-2026-44756 max-severity kernel EPP overflow lets unprivileged actors get admin on SAP via ICM. Onapsis: 10k+ internet-facing. Also S4GET CVE-2026-58240 unauth Message Server RCE. Patch Sep notes now. https://t.co/l1a1JEeOEJ

    @snakeyesV1

    8 Sept 2026

    97 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🛡️ #ExploitGrid Daily Threat Digest Top #Vulnerabilities (#CVEs) of the day CVE-2026-44756 CVE-2026-75650 CVE-2026-86296 CVE-2026-18922 CVE-2026-58240 ..🧵👇

    @exploitgrid

    8 Sept 2026

    74 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. SAP scores a described crash 10.0 and a described takeover 9.8, and the whole gap is one scope metric. September patch day: CVE-2026-44756 and CVE-2026-58240. No exploitation reported. https://t.co/5vpeh6itnD

    @severitydaily

    8 Sept 2026

    54 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. SAPは9月のセキュリティ更新で19件の新規Security Noteを公開し、4件のCritical脆弱性を含む計19件の問題を修正した。最重要はExtended Passport処理のメモリ破損脆弱性CVE-2026-44756である。 ほかのCriticalは、NetWeaver Message

    @yousukezan

    8 Sept 2026

    1055 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 CRITICAL: CVE-2026-44756 (CVSS 10.0) is a critical memory corruption vulnerability in SAP Extended Passport (EPP) Processing. The flaw can be exploited remotely by an unauthenticated attacker through a crafted network request containing a malformed EPP header, potentially

    @ThreatWire_

    8 Sept 2026

    122 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  7. CVE-2026-44756, a CVSS 10.0 SAP Extended Passport memory corruption vulnerability, lets unauthenticated attackers crash SAP systems. Patch now. #SAP #CVE202644756 #MemoryCorruption #Cybersecurity #PatchTuesday #Vulnerability #InfoSec https://t.co/g0l7ZCnCB4 https://t.co/ua6UQmB4

    @Daily_CyberSec

    8 Sept 2026

    185 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  8. CVE-2026-44756 A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit … https://t.co/r4ra45sfS0

    @CVEnew

    8 Sept 2026

    567 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

References

Sources include official advisories and independent security research.