SAP warns of maximum severity ‘OVERPASS’ kernel vulnerability

A Critical Flaw Exposed: SAP’s Overpass Vulnerability Threatens Enterprise Systems

German software giant SAP has issued critical security patches for its September 2026 update cycle, addressing 20 vulnerabilities across multiple products. Among these, a maximum-severity memory corruption flaw in the SAP Kernel code – known as “OVERPASS” – poses an immediate threat to enterprise systems worldwide.

The OVERPASS vulnerability allows attackers to execute arbitrary code on vulnerable systems, effectively granting them complete control over the affected system. This can be achieved through remote exploitation, making it a particularly insidious threat. The kernel is the core component of SAP’s software stack, responsible for managing access and interactions between various components and applications. Given its central role in system operations, any compromise here can have far-reaching consequences.

SAP has confirmed that the OVERPASS vulnerability affects several of its products, including SAP NetWeaver, SAP ERP Central Component (ECC), and SAP HANA. The affected systems are widely used across various industries, from finance to manufacturing, making this a widespread concern for organizations relying on these solutions. While SAP has not disclosed any specific instances of successful exploitation or public attacks leveraging this vulnerability, the sheer scope of its potential impact demands immediate attention.

To put this vulnerability into perspective: when an attacker successfully exploits OVERPASS, they can execute malicious code directly within the kernel, effectively bypassing security controls and gaining unrestricted access to system resources. This could allow them to exfiltrate sensitive data, disrupt operations, or even introduce malware that spreads across connected systems.

The SAP Kernel’s open-source nature makes it particularly vulnerable to attacks of this kind. While the company has taken steps to address the issue with its latest update, organizations relying on affected products must take immediate action to protect themselves against potential exploitation. This includes applying the relevant patches, conducting thorough vulnerability assessments, and implementing robust security measures to prevent lateral movement in case an attacker gains access.

In light of this critical flaw, it’s essential for enterprise IT administrators to prioritize patching their systems as soon as possible. Regular security audits and risk assessments can also help identify potential vulnerabilities before they’re exploited. As the threat landscape continues to evolve, staying vigilant and proactive is crucial for minimizing exposure to known and unknown threats alike.


Source: Bleeping Computer — 2026-09-08