Executive Summary

    On September 8th, 2026, SAP disclosed a critical vulnerability in the SAP kernel as part of its September Security Patch Day. Tracked as CVE-2026-44756, the vulnerability grants an unauthenticated attacker remote code execution on a target SAP host. SAP products are commonly deployed internet facing, and successful compromise provides threat actors initial access into an organization’s network.

    The vulnerability is in the Extended Passport Processing system, a core SAP component that exists in most SAP products, including Business Suite, NetWeaver, Enterprise Portal, Solution Manager, and others. In addition to initial access, these products often process critical business and client data, which would be immediately exposed on successful exploit.

    CVE-2026-44756 was discovered and reported by security company Onapsis, and security patches were available at time of public disclosure by SAP. No in-depth technical details or proof-of-concept exploit code are available at time of writing, and there are currently no reports of this exploit being used by threat actors in-the-wild. However, given the unauthenticated reach into business-critical systems, Beazley Security recommends affected organizations apply available fixes as soon as possible, prioritizing internet-facing systems.

    Affected Systems or Products

    Product

    Affected Versions

    Fixed Versions

    SAP KERNEL

    7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19, 9.20

    Addressed in SAP Note 374769

    SAP KRNL64UC

    7.22, 7.22EXT, 7.53, 8.04

    Addressed in SAP Note 374769

    SAP KRNL64NUC

    7.22, 7.22EXT

    Addressed in SAP Note 374769

    SAP WEBDISP

    9.16, 9.18, 9.19, 9.20

    Addressed in SAP Note 374769

    Mitigations / Workarounds

    Patching is the only effective remediation. Because the vulnerable EPP code is reachable over web requests, the SAP GUI protocol, and RFC connections, blocking any one protocol leaves the others open, and no network control should be treated as equivalent to the patch. Tightening SAP roles, user locks, or password policies have are also insufficient, as the vulnerable code runs before those checks are evaluated. Organizations should:

    1. 1.

      Inventory every system in the SAP landscape that runs an affected kernel, including Web Dispatcher instances.

    2. 2.

      Apply the kernel patch to internet-facing systems first, then to internal instances.

    3. 3.

      Remove unnecessary external exposure of SAP web interfaces while the rollout is in progress.

    4. 4.

      Maintain visibility into the SAP application layer so exploitation attempts can be detected and investigated before patching completes.

    Patches

    SAP released Security Note 3747649 on September 8th, 2026, covering the affected ABAP and Java kernels and the supported SAP Web Dispatcher releases. A single kernel patch closes the known exploitation vectors. Administrators should consult SAP’s September 2026 Security Patch Day guidance to determine which systems in their landscape require the update.

    Technical Details

    The Extended Passport is a core SAP component that facilitates tracing and troubleshooting. As a low-level mechanism, this object is created for every user session, before authentication. It is also active by default, without any changes to configuration. Additionally, the vulnerable code is reported to affect three critical interfaces:

    • Web layer, which handles HTTP based applications and integrations

    • SAP GUI layer, which handles SAP GUI logins

    • RFC layer, or Remote Function Call, which is how SAP systems programmatically communicate with each other and third-party integrations

    How Beazley Security is responding

    Beazley Security is monitoring client perimeter devices through our Exposure Management Platform to identify impacted devices and support organizations in remediation of any issues found.

    We are also conducting threat hunts across our MDR environment to detect potential exploitation attempts against our clients.

    If you believe your organization may have been impacted by this attack campaign and need support, please contact our Incident Response team.