SAP released its September 2026 security patches to address critical vulnerabilities. These flaws allow unauthenticated attackers to take full control of affected systems.
The OVERPASS vulnerability carries a maximum CVSS score of 10.0. The S4GET flaw carries a CVSS score of 9.8. Both vulnerabilities exist within the SAP kernel and NetWeaver Message Server.
These flaws enable remote code execution without requiring user credentials. The vulnerabilities bypass all standard security controls and affect products including S/4HANA.
Security researchers estimate over 10,000 internet-facing SAP systems are directly exposed. SAP urges customers to apply patches immediately as no effective workarounds exist.