By Craig Savage | September 16, 2026

SAP disclosed CVE-2026-44756, code-named OVERPASS, on Sept. 8, 2026, as part of its Security Patch Day advisory. It carries a CVSS score of 10.0, the highest severity rating the scale allows, describing worst-case damage wherever the vulnerable condition turns out to be present and reachable rather than confirming that any one customer has been compromised. In a landscape that runs order processing, financial closing and data shared with connected trading partners, this security update is worth taking seriously. Before reaching for a generic patch checklist, SAP customers need to review their own environment and determine the best mitigation steps.

What OVERPASS is and why it matters

OVERPASS affects how the SAP kernel processes Extended Passport data, a tracing structure attached to requests as they move through SAP systems. The vulnerable code runs before SAP evaluates logon credentials or authorization checks. A malformed request can trigger the flawed processing before a user is ever authenticated. Public research has described the issue as pre-authentication memory corruption that, in the worst case, may allow operating-system command execution under the privileges of the SAP installation account.

Publicly identified access routes include web traffic through the Internet Communication Manager and SAP Web Dispatcher, the SAP GUI dispatcher and RFC connections between systems. Internal systems are not automatically out of scope. A server reachable through a trusted internal path, an internal RFC connection or a test environment with looser controls can carry the same exposure as a system sitting on the open internet.

What public evidence shows

Public reporting on OVERPASS treats the flaw as serious. Onapsis, the security research firm that discovered the issue and disclosed it to SAP, has stated publicly that a specially crafted request can be used to take control of the receiving process and run operating system commands on the host, while the firm has withheld exploit details that would help attackers. As of publication, reviewed public sources did not show public executable exploit code or confirmed attacks in the wild.

The lack of confirmed public exploitation does not mean exposure reduction can wait. Once a vulnerability of this severity is publicly disclosed, customers should assume it will receive close attention and respond accordingly. Spinnaker Support recommends customers treat OVERPASS as a serious exposure assessment and control verification exercise instead of a patching announcement to schedule at convenience.

What SAP customers should do now

  • Determine applicability using the actual kernel and Web Dispatcher versions running in each environment. Product labels such as ECC or S/4HANA do not by themselves determine exposure.
  • Assess exposure across every access path, including web, SAP GUI, RFC, internal networks, test systems and disaster recovery environments.
  • Apply interim controls appropriate to each path. Filtering or removing client-supplied Extended Passport data can help address relevant web routes, though SAP GUI and RFC connections call for separate review and control decisions. In every case, controls need to act before a request reaches the vulnerable component.
  • Verify outcomes by confirming that headers are absent where expected, that blocked routes stay blocked and that business functions continue to operate normally.
  • Patch through SAP’s official remediation path. Only SAP can provide the vendor correction, and customers with active SAP maintenance should obtain and apply it through supported channels.

Keep a record of each step separately, including when guidance was received, when controls went live and when they were verified. Audit and incident response teams will ask for that record later, and a single vague timeline will not hold up under review.

Where Spinnaker Support can help

For SAP customers responding to OVERPASS, Spinnaker Support’s role is exposure management, helping customers scope their exposure, validate controls and prioritize next steps. A vulnerability of this severity raises real questions for organizations running environments that are complex, tightly integrated and not always simple to patch on short notice. That response should be measured, technically grounded, and specific to what is running in an organization’s environment.

Spinnaker Support can help SAP customers

  • Assess kernel version and patch level exposure, and confirm whether vulnerable services are reachable across web, SAP GUI and RFC paths.
  • Apply interim mitigation guidance appropriate to a customer’s specific architecture.
  • Define what to monitor for suspicious activity, exploitation attempts or control failure.
  • Prioritize next steps based on operational constraints and control posture.

 

For most organizations, the more useful question is whether the vulnerable condition is present, reachable and materially exposed in their own environment, not simply whether a patch exists. This is where Spinnaker Support adds value, helping customers translate a CVSS score into a plan built around their own systems, access paths and control posture.

For customers with active SAP maintenance, SAP remains the source of the vendor-issued correction. Spinnaker Support’s role is to help customers assess exposure, validate controls, and prioritize mitigation and monitoring around the issue. Patch execution should only be referenced where a specific managed services engagement explicitly includes that responsibility.

Spinnaker Support’s Cybersecurity Extension for SAP, powered by Layer Seven Security, supports visibility, exposure assessment, vulnerability management and monitoring across SAP landscapes, drawing on more than 5,000 built-in checks to help identify exposure and prioritize response. The offering helps customers gain faster visibility into where risk exists so they can prioritize response while remediation plans move forward. It does not replace the patch SAP issues, and it does not provide complete protection on its own. For incident response, Spinnaker Support can help customers think through escalation paths and monitoring considerations. A dedicated incident response engagement or compromise assessment typically calls for specialist expertise beyond that scope.

The strongest response to OVERPASS is an environment-specific plan, not a reaction driven by the CVSS score alone. It starts with understanding where exposure actually exists, reducing what is reachable, validating that controls hold under review, and following through with SAP’s approved remediation path. Customers who build that plan now will be in a stronger position to answer detailed questions the next time SAP issues a critical disclosure.

Craig Savage
Written By Craig Savage
Craig Savage Craig Savage leads cybersecurity at Spinnaker Support, bringing extensive experience in security transformation, Zero Trust, compliance and enterprise risk. His career includes leadership and consulting roles at Accenture, Capgemini, VMware and VMware Carbon Black. He is a recognized cybersecurity speaker and advisor known for aligning resilient security strategies with business priorities.