Summary
CVE-2026-44756 is a critical memory safety vulnerability in SAP Extended Passport (EPP) Processing. An unauthenticated attacker can send a crafted network request containing a malformed EPP header, potentially causing memory corruption, undefined behavior, and abnormal program termination. Successful exploitation can also allow an attacker to execute arbitrary operating system commands on the SAP host with SAP administrative privileges, potentially resulting in full compromise of SAP business data and processes.
The vulnerability affects multiple SAP kernel and Web Dispatcher versions and can be reached through web, SAP GUI, and RFC communication paths because EPP processing occurs before authentication. SAP addressed the vulnerability through Security Note 3747649 as part of the September 2026 Security Patch Day.
Urgent Actions Required
- Apply SAP Security Note 3747649 to affected SAP kernel and Web Dispatcher installations as soon as possible.
- Identify affected systems by checking the deployed SAP kernel release and patch level against the versions covered by Security Note 3747649.
- Prioritize internet-facing SAP systems for patching, followed by internal systems.
- Reduce network exposure where possible while remediation is in progress.
- Monitor the SAP application layer and network traffic for potential exploitation attempts, including malformed EPP headers and abnormal application termination.
- If patching is delayed, use the documented workaround in SAP Note 3756304 to prevent exploitation over HTTP traffic.
Which Systems Are Vulnerable to CVE-2026-44756?
Technical Overview
- Vulnerability Type:Memory Safety Vulnerability in Extended Passport Protocol (EPP) Processing
- Affected Software/Versions:
- KRNL64NUC: 7.22, 7.22EXT
- KRNL64UC: 7.22, 7.22EXT, 7.53, 8.04
- WEBDISP: 9.16, 9.18, 9.19, 9.20
- KERNEL: 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20
- CVSS Vector: v3.1
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Changed
- Confidentiality Impact: High
- Integrity Impact: High
- Availability Impact: High
- Patch Availability: Yes, available
How Does the CVE-2026-44756 Exploit Work?
The attack typically follows these steps:
What Causes CVE-2026-44756?
Vulnerability Root Cause:
CVE-2026-44756 results from missing boundary validation during the deserialization of Extended Passport Protocol (EPP) data. A malformed EPP header in a crafted network request can cause memory corruption during processing, potentially leading to undefined behavior and abnormal program termination.
How Can You Mitigate CVE-2026-44756?
If immediate patching is delayed or not possible:
- Apply the documented workaround in SAP Note 3756304 to prevent exploitation over HTTP traffic.
- Reduce network exposure to affected SAP systems where possible.
- Restrict access to SAP GUI through controlled network paths.
- Monitor the SAP application layer for exploitation attempts.
- Monitor network traffic for malformed EPP headers and review logs for abnormal application termination.
Which Assets and Systems Are at Risk?
- Asset Types Affected:
- SAP Kernel Systems - Systems running affected SAP kernel versions
- SAP Web Dispatcher - Affected WEBDISP versions processing EPP data
- SAP Web Layer - SAP systems using HTTP-based services such as Fiori, WebGUI, web services, and APIs
- SAP GUI Systems - Systems accepting SAP GUI connections
- RFC-Connected Systems - SAP systems using RFC connections for system-to-system communication
- Business-Critical Systems at Risk:
- SAP S/4HANA and SAP ERP systems - SAP business environments built on affected kernel components
- SAP NetWeaver systems - Including affected AS ABAP environments
- SAP BW/4HANA, Enterprise Portal, PI/PO, and Solution Manager - Kernel-based SAP products identified in the provided Onapsis reference
- Exposure Level:
- Internet-facing SAP systems - Particularly systems exposing SAP web interfaces or services
- Internal SAP systems - Systems accessible through SAP GUI or internal networks remain exposed even without direct Internet connectivity
- Systems with RFC connections - SAP environments using RFC communication can provide another path to the vulnerable EPP processing code
How Can You Detect CVE-2026-44756 Exploitation?
Exploitation Signatures:
- Malformed EPP headers in network traffic
- Abnormal application termination associated with EPP processing
Behavioral Indicators:
- Unexpected or malformed EPP requests
- Abnormal SAP application termination
Alerting Strategy:
- Priority: Critical
- Alert on malformed EPP headers and abnormal application termination
- Monitor the SAP application layer for exploitation attempts
Remediation & Response
- Remediation Timeline:
- Immediate: Identify affected SAP kernel and Web Dispatcher versions and prioritize internet-facing systems
- As soon as possible: Apply SAP Security Note 3747649
- If patching is delayed: Apply the documented HTTP workaround in SAP Note 3756304 and reduce network exposure
- Incident Response Considerations:
- Monitor the SAP application layer for exploitation attempts
- Review network traffic for malformed EPP headers
- Check logs for abnormal application termination
- Investigate suspicious activity involving affected SAP systems
Compliance & Governance Notes
- Audit Trail Requirement:
- Record affected SAP systems and their current kernel versions and patch levels during the remediation process.
- Document the application of SAP Security Note 3747649 for affected systems.
- Monitor and retain relevant logs for malformed EPP headers and abnormal application termination.
- Record and investigate suspicious activity involving affected SAP systems.
- Policy Alignment:
- Review network exposure of affected SAP systems and reduce unnecessary access where possible.
- Apply documented HTTP protections from SAP Note 3756304 if immediate patching is not possible.
- Do not rely on SAP authorizations or segregation-of-duties controls as protection against this vulnerability because the affected EPP processing occurs before authentication.
Get Full-Spectrum Visibility with Fidelis NDR
-
-
- Detect threats across all ports and protocols
- Correlate alerts for faster threat response
- Explore DLP, sandboxing, forensics, and threat intelligence
-
CVSS Breakdown Table
| Metric | Value | Description |
|---|---|---|
| Base Score | 10.0 | Maximum-severity vulnerability with network-based exploitation and high impact across confidentiality, integrity, and availability |
| Attack Vector | Network | The vulnerability can be triggered remotely through a crafted network request |
| Attack Complexity | Low | The CVSS assessment indicates that exploitation does not require complex conditions |
| Privileges Required | None | An attacker does not need to authenticate or have existing privileges to attempt exploitation |
| User Interaction | None | Exploitation does not depend on action from a user |
| Scope | Changed | Successful exploitation can affect resources beyond the security authority of the vulnerable component |
| Confidentiality Impact | High | Successful exploitation can result in significant exposure of confidential SAP data and information |
| Integrity Impact | High | Successful exploitation can allow significant unauthorized changes to SAP data or processes |
| Availability Impact | High | The vulnerability can cause abnormal program termination and, if successfully exploited for code execution, can significantly affect system availability |
References: