```

SAP has issued a critical security update for September 2026, patching 20 vulnerabilities across its product suite, with the most urgent concern being a maximum-severity flaw in its core kernel. The update, disclosed on 11 September and first reported by BleepingComputer, demands immediate attention from enterprise IT teams worldwide.

The top-priority fix addresses a memory corruption vulnerability tracked as OVERPASS in the SAP Kernel—the foundational layer that executes core system operations. Rated at the highest possible severity, this flaw allows attackers to corrupt system memory using crafted input, potentially leading to full system compromise without any authentication. Its broad impact affects multiple SAP products, including ERP, S/4HANA, and NetWeaver, making unpatched systems a high-value target.

Beyond the critical kernel flaw, the update includes 19 other security patches. These cover a range of issues such as privilege escalation, cross-site scripting, and SQL injection across various SAP applications. While none match the extreme severity of OVERPASS, together they represent a significant hardening effort for organizations relying on SAP for essential business processes.

The release highlights a persistent challenge in enterprise IT: securing complex, integrated software stacks. Kernel vulnerabilities like OVERPASS are especially dangerous as they strike at the heart of system stability. For IT administrators, this cycle requires prioritized testing and deployment, particularly in environments where SAP systems handle sensitive data or core operations.

For enterprises with substantial SAP footprints—including financial institutions, manufacturers, and logistics providers—this update is a critical maintenance task. The maximum-severity kernel flaw underscores the necessity of proactive vulnerability management across all sectors that depend on these critical systems.

The disclosure arrives amid rising cyber threats targeting enterprise software. Attackers consistently seek to exploit unpatched vulnerabilities to infiltrate corporate networks, making timely vendor updates a core defensive measure. The OVERPASS flaw, with its potential for remote code execution, illustrates why continuous monitoring of security advisories is essential.

IT and security teams are advised to review SAP's detailed notes and treat the OVERPASS patch as the highest priority. While thorough testing is recommended, the severity of the risk may justify expedited deployment in high-exposure environments. Maintaining disciplined patching cycles remains the most effective strategy to mitigate such threats before they can be exploited in attacks.


SAP 已於 2026 年 9 月發布重大安全更新,修補其產品套件中 20 個漏洞,其中最迫切關注的是其核心內核中的一個最高嚴重等級缺陷。這項於 9 月 11 日披露、並由 BleepingComputer 首先報導的更新,要求全球企業 IT 團隊立即關注。

優先處理的修補程式針對記憶體損壞漏洞,該漏洞在 SAP 內核中被追蹤為 OVERPASS——這是執行核心系統操作的基礎層。此缺陷評為可能的最高嚴重等級,攻擊者可透過特製輸入損壞系統記憶體,可能導致在未經任何驗證的情況下完全入侵系統。其廣泛影響涉及多個 SAP 產品,包括 ERP、S/4HANA 和 NetWeaver,使得未修補的系統成為高價值目標。

除了關鍵的內核缺陷外,此更新還包含 19 個其他安全修補程式。這些涵蓋了多種問題,例如各類 SAP 應用程式中的權限提升、跨網站腳本攻擊和 SQL 注入攻擊。儘管沒有任何漏洞的嚴重程度與 OVERPASS 相當,但它們共同代表了依賴 SAP 處理關鍵業務流程的組織的重大強化努力。

此更新凸顯了企業 IT 中一項持續存在的挑戰:保護複雜、整合的軟件堆疊。像 OVERPASS 這樣的核心漏洞尤其危險,因為它們直接衝擊系統穩定性。對於 IT 管理員而言,這個週期要求優先進行測試和部署,尤其是在 SAP 系統處理敏感數據或核心操作的環境中。

對於擁有大量 SAP 部署的企業——包括金融機構、製造商和物流供應商——此更新是一項關鍵的維護任務。這個最高嚴重等級的內核缺陷強調了所有依賴這些關鍵系統的行業必須主動進行漏洞管理的必要性。

此次披露正值針對企業軟件的網絡威脅不斷上升之際。攻擊者持續試圖利用未修補的漏洞滲透企業網絡,使得及時的供應商更新成為核心防禦措施。OVERPASS 缺陷具備遠端執行程式碼的潛力,說明了為何持續監控安全公告至關重要。

建議 IT 和安全團隊審查 SAP 的詳細說明,並將 OVERPASS 修補程式視為最高優先事項。雖然建議進行徹底測試,但風險的嚴重性可能證明在高曝險環境中加快部署是合理的。維持有紀律的修補週期仍然是在威脅被利用之前減輕此類風險的最有效策略。

新聞來源 / Original News Source