``` SAP has issued an emergency security patch for a critical memory corruption flaw in its core Kernel, scoring the maximum possible CVSS 10.0 rating, and is urging immediate action to prevent full system compromise.
Dubbed "OVERPASS," the vulnerability was patched in SAP's September 2026 security bundle, which addressed 20 flaws across multiple products. The critical flaw resides deep within the SAP Kernel, the foundational layer beneath the application software.
An attacker could remotely exploit this flaw to gain complete control over an affected system, enabling data theft, sabotage, or malware deployment. The primary danger lies in its kernel-level position. Exploits can operate below standard application-layer security monitoring and controls, making proactive patching the only reliable mitigation.
The issue impacts SAP Kernel versions 7.90, 8.00, and 8.10. For enterprises where SAP systems process critical financial, supply chain, and customer data, this represents a top-tier operational and compliance risk.
Action Checklist for IT Teams:
- Inventory: Immediately identify all SAP systems running Kernel versions 7.90, 8.00, or 8.10, with priority given to internet-facing and data-sensitive systems.
- Patch Deployment: Download and apply the September 2026 security patch from the SAP Support Portal. Test thoroughly in a non-production environment before full rollout.
- Verification: Post-patching, confirm the updated Kernel version to ensure remediation is successful.
- Monitoring: Maintain vigilant logging and monitoring for anomalous SAP system activity as a general security baseline.
- Broader Review: Assess the four other critical "hot news" vulnerabilities resolved in the September release as part of a comprehensive security hardening effort.
This "OVERPASS" flaw is the most critical fix in SAP's latest release, highlighting the persistent severity of threats targeting large-scale enterprise software. Organizations must act decisively to close this exposure.
SAP 已為其核心內核中的一個嚴重記憶體損壞漏洞發佈了緊急安全補丁,該漏洞獲得最高可能的 CVSS 10.0 評分,並敦促立即採取行動以防止系統被完全入侵。
被命名為「OVERPASS」的漏洞已在 SAP 2026 年 9 月的安全更新包中得到修補,該更新包解決了多個產品中的 20 個漏洞。這個嚴重漏洞深藏於 SAP 內核中,即應用軟件底下的基礎架構層。
攻擊者可利用此漏洞遠程完全控制受影響的系統,從而導致數據盜竊、系統破壞或惡意軟件部署。其主要危險在於其內核級別的位置。漏洞利用程序可能在標準應用層安全監控和控制之下運行,使得主動修補成為唯一可靠的緩解措施。
此問題影響 SAP 內核版本 7.90、8.00 和 8.10。對於使用 SAP 系統處理關鍵財務、供應鏈和客戶數據的企業而言,這代表了頂級的營運和合規風險。
IT 團隊行動清單:
- 資產盤點: 立即識別所有運行內核版本 7.90、8.00 或 8.10 的 SAP 系統,並優先處理互聯網外露和數據敏感的系統。
- 部署補丁: 從 SAP 支援入口網站下載並應用 2026 年 9 月的安全補丁。在全面推出前,請在非生產環境中進行充分測試。
- 驗證修補: 補丁部署後,確認更新後的內核版本,以確保修補成功。
- 持續監控: 作為一般安全基線,持續保持對 SAP 系統異常活動的警覺記錄和監控。
- 更廣泛評估: 評估 9 月版本中解決的另外四個嚴重「熱點」漏洞,作為全面安全加固工作的一部分。
此「OVERPASS」漏洞是 SAP 最新版本中最關鍵的修復,凸顯了針對大型企業軟件的威脅持續具嚴重性。各組織必須果斷行動,以關閉此安全缺口。
