SAP has released patches for multiple vulnerabilities across several business applications. Admins should apply the fixed versions promptly. There are no reports of active exploitation so far.
OVERPASS: CVSS 10 in SAP Applications
The most severe vulnerability, named "OVERPASS" by its discoverers at Onapsis, carries the maximum CVSS score of 10.0. An attacker with network access can send crafted requests without authentication, triggering application crashes. Additional critical flaws affect SAP NetWeaver (CVE-2026-58240, CVE-2026-66768), where attackers can bypass authentication and access credentials, and the SAP Cloud Application Programming Model (CVE-2026-76969).
Further Affected Products
High-severity vulnerabilities include SAP ABAP Developer Tools (CVE-2026-58243, privilege escalation) and SAP Commerce Cloud (CVE-2026-2332, information disclosure). Admins should check the SAP support portal for patches applicable to all products in use and install them without delay.