Key Facts

SAP’s September Security Patch Day bulletin lists CVE-2026-44756 as a Critical, CVSS 10.0 memory-corruption vulnerability in Extended Passport (EPP) Processing.

Technical Details

SAP lists affected kernel and Web Dispatcher versions in its bulletin. Onapsis’ technical analysis says the issue involves missing boundary validation while deserializing EPP data and may be reachable by unauthenticated attackers.

Impact & Mitigation

Apply SAP Security Note 3747649 and the relevant SAP Kernel updates. SAP’s bulletin also documents other September fixes; prioritize systems running the listed affected EPP components.

Sources

By Allan