SAP has released an urgent security update to patch a maximum-severity memory corruption vulnerability within its core Kernel, which it has designated "OVERPASS." The company is directing all customers to apply the patch without delay, as the flaw enables complete system compromise and carries a Common Vulnerability Scoring System (CVSS) score of 10.0.
Designated in SAP's September 2026 Security Notes and reported by BleepingComputer, the OVERPASS vulnerability resides in the foundational Kernel layer of SAP software. A successful exploit grants an attacker full control of the affected system. The high risk stems from its remote code execution capability, allowing a threat actor to run arbitrary commands on a server without physical access, potentially leading to data theft, ransomware, or a total system shutdown.
This critical fix is part of a broader September release from SAP that addresses 20 vulnerabilities across its product portfolio. The scale of the update highlights the continuous security maintenance required for large-scale enterprise software platforms.
SAP states there is no workaround for the OVERPASS flaw; applying the relevant Security Notes is the only mitigation. Remediation responsibility falls most heavily on organizations with on-premise SAP installations, where IT teams must manually test and deploy the patch. For customers on SAP's cloud services, the provider should handle the updates, but administrators are advised to verify their systems have received the fix.
The patch is crucial for any large enterprise relying on SAP for core operations like finance, logistics, and human resources. A compromise of these systems via OVERPASS could have severe operational consequences. Security teams must prioritize identifying all vulnerable SAP systems and begin emergency patching procedures immediately.
The OVERPASS fix is the most critical item in the release, which also contains patches for 19 other vulnerabilities of varying severity. This underscores that maintaining security on complex platforms requires consistent attention to monthly update cycles, not just during major emergencies.
Following disclosure on September 11, the immediate action for all on-premise SAP administrators is to review the official SAP Security Notes, prioritise the Kernel update, and deploy the patch as rapidly as possible within their change management process. Failure to do so leaves systems exposed to a trivial-to-exploit, maximum-severity threat.
SAP 已發佈緊急安全更新,以修補其核心 Kernel 中一個嚴重程度最高的記憶體損壞漏洞,該漏洞被命名為「OVERPASS」。該公司指示所有客戶立即應用此修補程式,因為此缺陷可導致系統被完全入侵,其通用漏洞評分系統(CVSS)分數達 10.0(滿分)。
根據 SAP 2026 年 9 月的 Security Notes(由 BleepingComputer 報導),OVERPASS 漏洞存在於 SAP 軟件的基礎 Kernel 層。成功利用此漏洞將賦予攻擊者對受影響系統的完全控制權。其高風險源於其 remote code execution 能力,允許威脅行為者在無需實體接觸的情況下,在伺服器上執行任意命令,可能導致資料被竊、勒索軟件攻擊或整個系統癱瘓。
此項關鍵修復是 SAP 較大規模 9 月發佈的一部分,旨在解決其產品組合中的 20 個漏洞。此次更新的規模突顯了大型企業軟件平台所需的持續安全維護。
SAP 聲稱針對 OVERPASS 缺陷沒有任何解決方法;應用相關的 Security Notes 是唯一的緩解措施。修復責任最重地落在那些進行本地部署(on-premise)SAP 安裝的組織身上,其 IT 團隊必須手動測試並部署修補程式。對於使用 SAP 雲端服務的客戶,服務提供商應處理更新,但建議管理員驗證其系統是否已收到修復。
此修補程式對於任何依賴 SAP 執行財務、物流及人力資源等核心運營的大型企業都至關重要。這些系統若因 OVERPASS 漏洞被入侵,可能帶來嚴重的營運後果。安全團隊必須優先識別所有易受攻擊的 SAP 系統,並立即啟動緊急修補程序。
OVERPASS 修復是此次發佈中最關鍵的項目,其中還包含針對另外 19 個不同嚴重程度漏洞的修補程式。這突顯了在複雜平台上維護安全,需要持續關注每月的更新週期,而不能僅在重大緊急情況下才進行。
於 9 月 11 日披露後,所有本地部署 SAP 管理員的立即行動應是查閱官方 SAP Security Notes,優先處理 Kernel 更新,並在其變更管理流程內盡快部署修補程式。未能這樣做將使系統暴露於一個易於利用的嚴重威脅之下。
