Key Facts
SAP’s September Security Patch Day bulletin lists CVE-2026-44756 as a Critical, CVSS 10.0 memory-corruption vulnerability in Extended Passport (EPP) Processing.
Technical Details
SAP lists affected kernel and Web Dispatcher versions in its bulletin. Onapsis’ technical analysis says the issue involves missing boundary validation while deserializing EPP data and may be reachable by unauthenticated attackers.
Impact & Mitigation
Apply SAP Security Note 3747649 and the relevant SAP Kernel updates. SAP’s bulletin also documents other September fixes; prioritize systems running the listed affected EPP components.
