HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Remote Code Execution Vulnerability Discovered in SAP Extended Passport (EPP) Processing (CVE‑2026‑44756)

A deserialization flaw (CVE‑2026‑44756) in SAP Extended Passport processing allows unauthenticated attackers to execute arbitrary OS commands with full SAP admin rights. The bug spans many kernel releases, making timely patching and evidence‑driven control mapping essential for audit readiness.

Verisq™ Intelligence · 📅 September 10, 2026 · 📰 cisecurity.org
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
2 sector(s)
Actions
4 recommended
📰
Source
cisecurity.org

Remote Code Execution Vulnerability Discovered in SAP Extended Passport (EPP) Processing (CVE‑2026‑44756)

What Happened — A deserialization flaw in SAP’s Extended Passport (EPP) processing (CVE‑2026‑44756) allows an unauthenticated attacker to send crafted RFC or HTTP requests that trigger arbitrary OS‑level command execution with full SAP administrative privileges. The bug exists in multiple SAP kernel releases and is reachable from the GUI, RFC, and web layers. No public exploitation has been reported yet.

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for a continuous vulnerability‑management control that tracks, patches, and validates remediation of critical kernel components across all SAP landscapes.
  • Highlights the importance of evidence‑driven control mapping: organizations must be able to prove that patch‑deployment, configuration baselines, and monitoring are in place to satisfy audit requirements.
  • Aligns with the Verisq capability Control Mapping, which automates collection of remediation evidence and maps it to the Verisq Common Framework (VCF) control objective for secure system configuration.

Who Is Affected – Large and medium enterprises, government agencies, and any organization running SAP ERP/S/4HANA environments that include the listed kernel versions.

Recommended Actions

  • Apply SAP’s security patch for CVE‑2026‑44756 immediately (or follow SAP’s mitigation guidance if patching is delayed).
  • Verify that all affected kernel versions are identified in your asset inventory and that patch status is recorded as audit evidence.
  • Enhance monitoring of EPP‑related logs for anomalous RFC/HTTP traffic and enable alerting on unexpected process launches.
  • Conduct a rapid risk assessment to determine potential impact on critical business processes and update your control‑assurance documentation accordingly.

Source: CIS Advisory 2026‑092

Technical Notes – The vulnerability stems from missing boundary validation during deserialization of EPP data (memory‑safety violation). It is classified under ATT&CK T1190 (Exploit Public‑Facing Application) and can be triggered via the SAP GUI, RFC, or Internet Communication Manager. Affected kernel releases include KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, KRNL64 7.53, 8.04, WEBDISP 9.16‑9.20, and KERNEL 7.22‑9.20.

Source: CIS Advisory 2026‑092

📰 Original Source
https://www.cisecurity.org/advisory/a-vulnerability-in-sap-extended-passport-epp-processing-could-allow-for-remote-code-execution_2026-092

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →