critical2026-09-08SAP Kernel / Web DispatcherCVE-2026-44756

Memory Corruption via Malformed Extended Passport Header

SAP Kernel / SAP Web Dispatcher

Our Take

CVSS 10.0 hitting the SAP Kernel is as bad as it gets. EPP headers are processed before any authentication, meaning every internet-facing SAP system — AS ABAP, AS Java, Web Dispatcher — is exposed. Kernel 7.22 covers systems back to 2004, so virtually every SAP shop is in scope. The Web Dispatcher being separately listed means it needs its own patch pass. Do not wait for your next maintenance window.

Vulnerability Detail

Missing boundary validation during deserialization of Extended Passport (EPP) data. A crafted network packet with a malformed EPP header triggers a memory safety violation. No authentication required, low attack complexity, network reachable.

Patch Action

Apply SAP Kernel patch and Web Dispatcher patch from SAP Note 3747649 immediately. Both components must be patched separately.

Affected Versions

KERNEL 7.22–9.20 (ABAP & Java)
KRNL64NUC
KRNL64UC; WEBDISP 9.16–9.20

Patch Info

Priority

🔴 Patch immediately

CVSS Score

10

SAP Note

3747649

CVE

CVE-2026-44756

Published

2026-09-08

← All patches