SAP has issued a high-priority security update to address a maximum-severity memory corruption flaw in its core Kernel, which could allow attackers to fully compromise systems running the software giant's enterprise platforms. The urgent patch was part of SAP's September 2026 security release.

According to an advisory covered by BleepingComputer, the vulnerability, tracked as CVE-2026-41023 and dubbed "OVERPASS," was assigned a CVSS score of 10.0—the highest possible severity. The flaw resides in the SAP Kernel, the foundational layer of the company's product stack, making any compromise potentially catastrophic for affected organizations.

A successful exploit of this memory corruption issue could enable remote code execution, granting an attacker the ability to take complete control of the host server. This presents an immense risk for the thousands of large enterprises globally that rely on SAP's ERP software, such as S/4HANA and NetWeaver, to manage core business functions including finance, supply chain, and human resources.

The vulnerability was identified by security researchers from Onapsis, who coordinated its disclosure with SAP. The discovery underscores the ongoing security scrutiny of complex, widely-deployed enterprise systems. The flaw is considered internet-facing, meaning servers exposed directly to the internet are at heightened risk of immediate exploitation if not patched.

This particular issue was one of 20 security notes published by SAP in its September Patch Tuesday cycle, though the OVERPASS kernel flaw stands out due to its critical rating. For enterprises relying on SAP for mission-critical operations, the vulnerability represents a direct threat to operational integrity and data security.

Security teams are urged to apply the provided patches immediately. The foundational nature of the Kernel means a single successful exploit could cascade across an entire SAP landscape, potentially disrupting vast business networks. Failure to address this vulnerability in a timely manner leaves organizations exposed to significant operational, financial, and reputational damage from a full system compromise.


SAP 已發布高優先級安全更新,以解決其核心 Kernel 中一個最高嚴重性的記憶體損壞漏洞,攻擊者或可藉此完全入侵運行這家軟件巨頭企業平台的系統。此次緊急修補是 SAP 2026年9月安全發佈的一部分。

根據 BleepingComputer 報導的一則安全通告,該漏洞編號為 CVE-2026-41023,代號為「OVERPASS」,其 CVSS 評分為10.0分——即最高可能的嚴重級別。漏洞存在於 SAP 核心中,該核心是公司產品堆疊的基礎層,因此任何入侵對受影響組織而言都可能造成災難性後果。

成功利用此記憶體損壞問題可實現遠程代碼執行,使攻擊者能夠完全控制主機伺服器。這對全球數千家依賴 SAP 的 ERP 軟件(如 S/4HANA 和 NetWeaver)管理財務、供應鏈及人力資源等核心業務職能的大型企業構成巨大風險。

該漏洞由 Onapsis 的安全研究人員發現,並與 SAP 協調披露。這一發現突顯了對複雜且廣泛部署的企業系統持續進行安全審查的重要性。該漏洞被認為具有互聯網暴露面,這意味著直接面向互聯網的伺服器若未及時修補,將面臨更高的被即時利用風險。

此特定問題是 SAP 在2026年9月補丁星期二週期內發布的20則安全說明之一,但 OVERPASS 核心漏洞因其關鍵評級而格外突出。對於依賴 SAP 處理關鍵業務的企業而言,該漏洞直接威脅其營運完整性與數據安全。

安全團隊被敦促立即套用所提供的修補程式。由於核心的基礎性質,單一成功的漏洞利用可能在整個 SAP 景觀中產生連鎖反應,潛在中斷廣泛的業務網絡。未能及時處理此漏洞將使組織面臨因全面系統入侵而導致的重大營運、財務及聲譽損害。

新聞來源 / Original News Source