Home / Sep 10, 2026 / Story
0
#9 The Hacker News general September 09, 2026 at 06:25 UTC

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

By [email protected] (The Hacker News)

AI Summary

SAP patched CVE-2026-44756, a CVSS 10.0 memory corruption vulnerability in SAP Extended Passport (EPP) Processing that enables unauthenticated remote code execution with severe impact on confidentiality, integrity, and availability. A maximum CVSS score combined with no authentication requirement makes this an immediate patching priority for any organization running SAP EPP. SAP customers should apply September 2026 Security Patch Day updates without delay.

Relevance score: 83.0/100

# More from September 10