← back

CVE-2026-44756

CRITICAL · 10.0 EPSS 0.3%
hype LIKELY HACK · 72 hack

Vendor patching same-day, no PoC public, no KEV; early advisory uptake.

What: Memory safety vulnerability in SAP Extended Passport Protocol (EPP) processing library allowing unauthenticated remote code execution or DoS; CVSS 10.0 CRITICAL.

Why it matters: Published today with CVSS 10.0, SAP has released a patch. No KEV listing yet, no public PoC confirmed in posts, but vendor advisory and urgent patch availability signal real vulnerability requiring immediate triage by SAP customers. All major posts reference SAP's official patch day announcement.

Where it's seen: Coordinated social media amplification across multiple platforms (Bluesky, German security outlets, Japanese and English infosec accounts) citing SAP Security Patch Day September 2026, vendor advisory links, and patch availability. Chatter is factual and patch-focused, not speculative.

RISK: CRITICAL — Unauthenticated network exploit, CVSS 10.0, SAP patch released same day.

Generated by claude-haiku-4-5 from public posts and authoritative metadata. AI can make mistakes — verify against vendor advisories before acting. 9/8/2026, 1:33:08 PM

Description

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

CVSS 3.1 breakdown

Exploitability 3.9 · Impact 6.0
vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack vector
Network
Complexity
Low
Privileges required
None
User interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Weaknesses