HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical CVSS 10.0 Unauthenticated RCE in SAP Extended Passport (CVE‑2026‑44756) Threatens Enterprise ERP Systems

SAP released patches for CVE‑2026‑44756, a memory‑corruption flaw in the Extended Passport component that enables unauthenticated remote code execution. The vulnerability affects all supported SAP ERP versions and could compromise confidentiality, integrity, and availability. Organizations must prove they can remediate such critical flaws to satisfy audit and regulatory expectations.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
3 recommended
📰
Source
thehackernews.com

Critical CVSS 10.0 Unauthenticated RCE in SAP Extended Passport (CVE‑2026‑44756) Threatens Enterprise ERP Systems

What It Is — SAP has disclosed a memory‑corruption flaw in the Extended Passport (EPP) processing component that allows an unauthenticated attacker to execute arbitrary code on the underlying host.

Exploitability — The vulnerability is publicly disclosed, has a CVSS 10.0 base score, and proof‑of‑concept code has been shared in the advisory. No known active exploit campaigns have been reported yet, but the severity warrants immediate remediation.

Affected Products — All supported versions of SAP ERP that include the Extended Passport module (e.g., SAP S/4HANA, SAP ECC, SAP Business Suite).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a vulnerability‑management control that ensures timely detection, assessment, and remediation of critical vendor‑issued flaws.
  • Provides audit‑ready evidence of patch cadence, a key indicator of due‑diligence for regulators and enterprise buyers.
  • Supports continuous control monitoring by linking patch deployment to a unified control framework, enabling a single control objective to satisfy multiple compliance regimes (e.g., NIST CSF, ISO 27001).

Recommended Actions

  1. Deploy SAP’s security patches for CVE‑2026‑44756 without delay.
  2. Verify patch installation across all ERP instances using automated inventory tools and capture evidence for audit trails.
  3. Incorporate SAP security advisories into your vulnerability‑management workflow to ensure future critical updates are tracked and remediated promptly.

Source: The Hacker News – SAP patches CVSS 10.0 kernel flaw

📰 Original Source
https://thehackernews.com/2026/09/sap-patches-cvss-100-kernel-flaw.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →