<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[SAP warns of maximum severity 'OVERPASS' kernel vulnerability]]></title><description><![CDATA[<p dir="auto">SAP’s September 2026 security patch batch tackles 20 vulnerabilities across its product lineup, with the spotlight falling on a critical memory corruption issue buried in the SAP Kernel. Tracked as maximum severity, the flaw—dubbed “OVERPASS”—can be triggered by an authenticated attacker, potentially leading to full system compromise or unauthorized privilege escalation. Given the kernel’s central role in running SAP applications, the risk is particularly acute for on-premise deployments where the attack surface is broader.</p>
<p dir="auto">The update spans several core components, including SAP NetWeaver, SAP S/4HANA, and SAP Business Technology Platform, though the kernel fix takes priority due to its exploitability. SAP has flagged the vulnerability as requiring immediate attention, recommending that administrators review their current kernel patch levels and apply the relevant support package stacks without delay. No workarounds were provided, meaning the patch is the only viable path to remediation.</p>
<ul>
<li>The most critical issue is a kernel-level memory corruption vulnerability, rated 10.0 on the CVSS scale.</li>
<li>Other patches address cross-site scripting, information disclosure, and denial-of-service issues, with lower severity ratings.</li>
<li>SAP users should check their system’s kernel version against the September 2026 Support Package Stack release notes.</li>
</ul>
<p dir="auto">For those running hybrid or cloud environments, SAP notes that some fixes are automatically applied, but on-premise customers must manually deploy the updates. As always, it’s wise to test patches in a sandbox environment before rolling them out to production, given the kernel’s role in system stability.</p>
<p dir="auto">Source: <a href="https://www.bleepingcomputer.com/news/security/sap-warns-of-maximum-severity-overpass-kernel-vulnerability" target="_blank" rel="noopener noreferrer nofollow ugc">Unknown</a></p>
<p dir="auto">Is your SAP landscape running the latest kernel patch, or are you deferring the update due to change-management constraints?</p>
]]></description><link>https://xploitlk.com/topic/263/sap-warns-of-maximum-severity-overpass-kernel-vulnerability</link><generator>RSS for Node</generator><lastBuildDate>Sat, 12 Sep 2026 06:09:58 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/263.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 08 Sep 2026 16:30:27 GMT</pubDate><ttl>60</ttl></channel></rss>