Lily
Anne

SAP Kernel and Message Server Bugs Threaten Core Business Systems

Lily Anne

Sep 11, 2026

5 min read

SAP Kernel and Message Server Bugs Threaten Core Business Systems

TL; DR

Two critical SAP vulnerabilities, OVERPASS and S4GET, allow unauthenticated remote exploitation and can lead to operating system command execution on affected systems.

  • Enterprises should identify exposed SAP Kernel and NetWeaver Message Server components, apply SAP Security Notes 3747649 and 3759472, and review network reachability.
  • Patching should be paired with investigation for suspicious registrations, commands, connections, and signs of earlier compromise.
  • Hexnode UEM and XDR can support the wider response through endpoint compliance, administrative-device hardening, threat investigation, and manual containment actions.

A SAP critical vulnerability alert deserves immediate attention when attackers can reach business systems without logging in. On September 9, 2026, CERT-EU published advisory 2026-011 covering two flaws in SAP Kernel and NetWeaver Message Server. Both allow remote exploitation without authentication.

For enterprises, the concern extends beyond server availability. SAP environments can hold financial records, employee information and operational workflows. Security teams should coordinate with SAP administrators to identify affected components, prioritize remediation and assess potential exposure.

Strengthen Endpoint Security with Hexnode UEM

OVERPASS: Memory corruption in SAP Kernel

CVE-2026-44756, or OVERPASS, carries a CVSS score of 10.0. It affects SAP Extended Passport processing in the Kernel. Missing boundary validation during deserialization allows an unauthenticated attacker to submit malformed EPP data through a crafted network request.

Onapsis, which discovered the flaw, describes the potential for arbitrary operating system command execution with SAP administrative privileges. That access can expose underlying business data and processes to compromise. Teams should evaluate the affected technical components across their SAP estate, including systems outside production.

S4GET: Missing authentication in Message Server

CVE-2026-58240, or S4GET, carries a CVSS score of 9.8. NetWeaver Message Server fails to sufficiently authenticate internal application server components during registration. An attacker with network access can register unauthorized components. CERT-EU cites researchers’ findings that exploitation can enable command execution under the operating system account running SAP.

This makes network reachability a central assessment question. Review which users, devices and network segments can contact the affected service.

cybersecurity-kit

Cybersecurity kit

Access essential cybersecurity resources to strengthen security, reduce risk, and improve cyber resilience.

Download the Resource Kit

Why does this matter to enterprise security teams?

A compromised SAP environment can interrupt transactions, expose sensitive records or undermine business processes. Even a short disruption can create backlogs across finance, procurement and logistics.

The authentication gap also changes the defensive priority. Strong user passwords cannot address a service that accepts unauthenticated malicious requests. Teams need to fix the vulnerable component and reduce unnecessary exposure.

Treat remediation as a shared operational task. SAP administrators own component updates, network teams review connectivity, and security teams investigate evidence of compromise. Business owners should help prioritize systems whose interruption would create the greatest impact.

How should enterprises respond?

Use a coordinated remediation checklist:

  • Inventory affected components. Record Kernel and Message Server versions across production, development, testing and disaster recovery environments.
  • Apply the relevant fixes. CERT-EU recommends SAP Security Note 3747649 for OVERPASS and 3759472 for S4GET. Follow each note’s applicability and update instructions.
  • Review network exposure. Limit unnecessary connectivity while preserving required SAP communication. Test changes with application owners.
  • Investigate suspicious activity. Review available SAP, operating system and network records for unexpected component registrations, commands or connections.
  • Validate recovery. Confirm updated component levels and test business workflows. Investigate evidence of earlier compromise separately from patch verification.

How can Hexnode reduce the wider enterprise risk?

Hexnode can support security teams managing endpoints used to access or administer business systems.

Enterprise priority Hexnode capability Practical application
Identify endpoint security gaps Hexnode UEM Compliance & Patch Management Track patch status across supported devices, identify missing OS updates, and assess passcode compliance and encryption status, subject to platform support.
Harden administrative devices Hexnode UEM Security & Hardening Policies Configure BitLocker on Windows and FileVault on macOS, enforce supported OS updates and firewall settings, and apply platform-specific application restrictions across Windows, macOS and Linux.
Investigate endpoint threats Hexnode XDR Automatically correlate endpoint signals and provide cross-endpoint visibility across supported Windows and macOS devices to help analysts investigate related suspicious activity.
Contain identified threats Hexnode XDR Use one-click Isolate Device, Kill Process and Quarantine File actions to contain threats and help prevent lateral movement. Configured event-driven workflows can also trigger supported isolation and process-termination actions.

SAP Security Notes 3747649 and 3759472 address the vulnerabilities in core SAP server components, while Hexnode helps secure the supported admin workstations, jump boxes and user endpoints that access those systems. SAP administrators must apply the relevant fixes and validate server integrity. Teams should also enforce SAP access restrictions through appropriate identity and network controls, validating any device-compliance integration before relying on it.

FAQs

Both vulnerabilities can be exploited remotely without authentication against affected SAP components. Successful exploitation can lead to operating system command execution, which can expose sensitive data and disrupt critical business processes.

SAP Security Note 3747649 addresses CVE-2026-44756, also known as OVERPASS. SAP Security Note 3759472 addresses CVE-2026-58240, or S4GET, and organizations should follow each note’s applicability and update guidance.

Strong passwords do not prevent exploitation when a vulnerable service accepts malicious requests without authentication. Organizations must remediate the affected SAP components and reduce unnecessary network exposure.

Close the exposure and verify integrity

Prioritize affected SAP systems according to business impact and reachability. Apply the relevant updates, confirm successful deployment and examine signs of unauthorized activity. A complete response combines vulnerability remediation with evidence that critical business systems remain trustworthy.

Share

Lily Anne

Content writer at Hexnode. Fueled by good coffee and the occasional cat cuddle, I enjoy crafting content that informs, connects, and resonates. Nothing excites me more than knowing my words have been read, appreciated, and maybe even bookmarked.