SAP has urged customers to deploy an emergency patch for a maximum-severity memory corruption flaw within its core kernel code, tracked as 'OVERPASS'. The vulnerability, which received the highest possible CVSS score of 10.0, allows a remote, unauthenticated attacker to potentially take full control of affected servers.
The flaw resides in the SAP Kernel, the foundational layer supporting a wide range of products including ERP, Business Suite, and S/4HANA systems. A compromise at this level creates a systemic risk, enabling an attacker to bypass application-layer security and disrupt critical business operations.
The September 2026 security bundle addresses 20 vulnerabilities in total. The OVERPASS kernel flaw is distinguished by its trivial exploitability: it can be triggered over a network without requiring any credentials, making any exposed SAP instance a prime target.
In its advisory, SAP chose not to disclose specific technical details of the corruption to prioritize patch adoption. The incident highlights the persistent challenge of memory safety bugs in complex enterprise infrastructure. Such kernel-level vulnerabilities, while less common than application bugs, require the most urgent response due to their profound impact.
Immediate Action Required
Organizations are strongly advised to prioritize the installation of the September 2026 kernel patch. SAP recommends downloading the update via the SAP Support Portal and the SAP Software Download Center. Administrators must verify patch coverage across all development, staging, and production environments.
The wide reach of the SAP Kernel means this is an urgent operational priority for sectors including finance, manufacturing, and logistics. Delayed patching leaves core business infrastructure exposed to a straightforward remote compromise scenario, underscoring the critical need for swift remediation.
SAP 敦促客戶部署針對其核心程式碼中最高嚴重程度記憶體損毀漏洞的緊急修補程式,該漏洞代號為「OVERPASS」。此漏洞獲得最高可能的 CVSS 評分 10.0,可能允許遠端未經身份驗證的攻擊者完全控制受影響的伺服器。
該漏洞存在於 SAP Kernel (核心) 中,這是支撐包括 ERP、Business Suite 及 S/4HANA 系統在內眾多產品的基礎層。此層級的系統遭入侵將帶來系統性風險,使攻擊者能繞過應用程式層級安全機制並中斷關鍵業務運作。
2026 年 9 月安全更新共修復了 20 個漏洞。OVERPASS 核心漏洞因其極易被利用而突出:它可透過網絡觸發,無需任何憑證,這使得任何公開的 SAP 實例成為主要攻擊目標。
在其安全公告中,SAP 選擇不披露此次損毀的具體技術細節,以優先推動修補程式的採用。此事件突顯了複雜企業基礎設施中記憶體安全漏洞所帶來的持續挑戰。此類核心層級漏洞雖然比應用程式漏洞少見,但因其深遠影響,需要最緊急的處理。
須立即採取行動
強烈建議各機構優先安裝 2026 年 9 月核心修補程式。SAP 建議透過 SAP Support Portal 和 SAP Software Download Center 下載更新。管理員必須驗證修補程式是否覆蓋所有開發、測試及生產環境。
SAP Kernel 的廣泛影響力意味著這是金融、製造及物流等行業的緊急營運要務。延遲修補將使核心企業基礎設施暴露於直接的遠端入侵風險之下,凸顯了迅速補救的關鍵必要性。
