SAP has issued an urgent security update addressing a maximum-severity memory corruption vulnerability in its core kernel, a flaw already being exploited by attackers. The vulnerability, tracked as CVE-2026-48125 and dubbed "OVERPASS," carries the highest possible CVSS base score of 10.0, signifying a critical, immediate risk to enterprise systems.

The flaw exists within the fundamental SAP Kernel code, a component that underpins a wide range of the company's flagship products. According to an advisory published by BleepingComputer on 11 September, successful exploitation could allow an unauthenticated attacker to take complete control of the affected system.

The universal impact of the vulnerability is significant. Because the kernel is foundational, the OVERPASS flaw affects a broad spectrum of critical enterprise platforms, including SAP S/4HANA, SAP NetWeaver, and older Business Suite releases. This places a vast number of business-critical installations worldwide at potential risk. The advisory warns that exploitation could lead to full compromise of confidentiality, integrity, and availability of the affected system.

The September 2026 patch batch released by SAP contains fixes for 20 vulnerabilities across multiple products. However, the OVERPASS kernel flaw stands out as the headline issue requiring immediate priority.

SAP strongly recommends that administrators apply the necessary patches without delay. The standard procedure of first testing updates in a non-production environment should be followed, but the urgency of this patch cannot be overstated given its active exploitation. In scenarios where immediate patching is not feasible, implementing recommended workarounds is advised as a temporary measure to mitigate risk.

The disclosure of active exploitation elevates this from a routine update to a time-sensitive security alert for IT teams. Organizations running SAP software should initiate emergency patching procedures and prioritize systems based on their exposure and business criticality.


SAP 已發布緊急安全更新,以解決其核心內核中一個最高嚴重程度的記憶體損壞漏洞,此缺陷已遭攻擊者積極利用。該漏洞追蹤編號為 CVE-2026-48125,被命名為「OVERPASS」,其 CVSS 基礎分數獲得最高的 10.0 分,意味著對企業系統構成緊急且嚴重的風險。

此漏洞存在於 SAP 核心內核代碼中,該組件支撐著該公司多項旗艦產品。根據 BleepingComputer 於 9 月 11 日發布的公告,成功利用此漏洞可能使未經授權的攻擊者完全控制受影響系統。

該漏洞的影響範圍極具普遍性。由於內核是基礎組件,OVERPASS 缺陷影響範圍廣泛,涵蓋多個關鍵企業平台,包括 SAP S/4HANA、SAP NetWeaver 以及較舊的 Business Suite 版本。這使得全球大量業務關鍵系統面臨潛在風險。公告警告,利用此漏洞可能導致受影響系統的機密性、完整性及可用性遭到完全破壞。

SAP 於 2026 年 9 月發布的補丁批次包含針對多個產品中 20 個漏洞的修復。然而,OVERPASS 內核漏洞作為首要問題脫穎而出,需立即優先處理。

SAP 強烈建議管理員毫不延遲地應用必要的補丁。應遵循標準程序,先在非生產環境中測試更新,但鑑於此漏洞已被積極利用,其補丁的緊迫性再怎麼強調也不為過。若立即安裝補丁不可行,建議採取推薦的解決方案作為臨時措施以降低風險。

漏洞被積極利用的披露,使此事件從常規更新轉變為 IT 團隊需即時關注的安全警報。運行 SAP 軟件的組織應啟動緊急補丁程序,並根據系統暴露程度及業務關鍵性確定優先級。

新聞來源 / Original News Source