SAP Addresses Critical CVSS 10.0 Vulnerability in Kernel Allowing Unauthenticated RCE
SAP has addressed a critical CVSS 10.0 vulnerability (CVE-2026-44756) in its kernel, enabling unauthenticated remote code execution through memory corruption in Extended Passport processing. Multiple other high-severity flaws, including CVE-2026-58240 and others, were also patched to mitigate risks of data exposure and system compromise.
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application
The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP
*** END OF TRANSMISSION ***