A critical vulnerability in SAP’s kernel has been patched, exposing thousands of businesses worldwide to unauthenticated remote code execution attacks. The flaw, rated CVSS 10.0 – the highest severity rating possible – allows malicious actors to bypass security controls and execute arbitrary code on compromised systems.
The vulnerability affects a wide range of SAP products, including ERP (Enterprise Resource Planning), CRM (Customer Relationship Management), and PLM (Product Lifecycle Management) solutions. According to SAP’s own estimates, over 300,000 customers are potentially impacted by this flaw, with many more likely at risk due to the widespread adoption of their software.
So how does this vulnerability work? In brief, it takes advantage of a weakness in SAP’s kernel architecture that allows attackers to inject malicious code into system processes. This is achieved through a combination of cross-domain privilege escalation and remote code execution techniques, which can be executed with no prior authentication or authorization required. Put simply, an attacker can remotely access and control a vulnerable SAP system as if they were a legitimate user.
The implications are severe. If exploited, this vulnerability could enable attackers to gain complete control over an organization’s IT infrastructure, allowing them to steal sensitive data, disrupt operations, or even hold the system for ransom. The fact that no authentication is required makes it particularly worrying, as attackers can launch attacks from anywhere in the world without being detected.
SAP has taken swift action to address this vulnerability by releasing a patch and urging customers to apply it immediately. While this move should alleviate some of the pressure on affected organizations, it’s essential to remember that patches are only effective if applied correctly and in a timely manner. Organizations must also ensure they have robust security controls in place to prevent similar attacks in the future.
The severity of this vulnerability serves as a stark reminder of the importance of regular software updates and robust cybersecurity practices. As attackers become increasingly sophisticated, it’s crucial for organizations to stay one step ahead by prioritizing patch management, implementing robust access controls, and conducting regular security audits.
In light of this latest development, we recommend that SAP customers prioritize patching their systems as soon as possible and review their existing security protocols to ensure they are adequately prepared to prevent similar attacks. By taking proactive steps to protect themselves, organizations can minimize the risk of a successful attack and maintain business continuity in an increasingly hostile cybersecurity landscape.
Source: The Hacker News — 2026-09-09