Cybersecurity & Protection

SAP Patch Day: Critical CVSS 10 Flaw in Business Software

Oct 1, 2026 1 min read
All articles

SAP has released patches for multiple vulnerabilities across several business applications. Admins should apply the fixed versions promptly. There are no reports of active exploitation so far.

OVERPASS: CVSS 10 in SAP Applications

The most severe vulnerability, named "OVERPASS" by its discoverers at Onapsis, carries the maximum CVSS score of 10.0. An attacker with network access can send crafted requests without authentication, triggering application crashes. Additional critical flaws affect SAP NetWeaver (CVE-2026-58240, CVE-2026-66768), where attackers can bypass authentication and access credentials, and the SAP Cloud Application Programming Model (CVE-2026-76969).

Further Affected Products

High-severity vulnerabilities include SAP ABAP Developer Tools (CVE-2026-58243, privilege escalation) and SAP Commerce Cloud (CVE-2026-2332, information disclosure). Admins should check the SAP support portal for patches applicable to all products in use and install them without delay.