CVE-2026-44756
CRITICAL · 10.0 EPSS 0.3%Vendor patching same-day, no PoC public, no KEV; early advisory uptake.
What: Memory safety vulnerability in SAP Extended Passport Protocol (EPP) processing library allowing unauthenticated remote code execution or DoS; CVSS 10.0 CRITICAL.
Why it matters: Published today with CVSS 10.0, SAP has released a patch. No KEV listing yet, no public PoC confirmed in posts, but vendor advisory and urgent patch availability signal real vulnerability requiring immediate triage by SAP customers. All major posts reference SAP's official patch day announcement.
Where it's seen: Coordinated social media amplification across multiple platforms (Bluesky, German security outlets, Japanese and English infosec accounts) citing SAP Security Patch Day September 2026, vendor advisory links, and patch availability. Chatter is factual and patch-focused, not speculative.
RISK: CRITICAL — Unauthenticated network exploit, CVSS 10.0, SAP patch released same day.
Description
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Changed
- Confidentiality
- High
- Integrity
- High
- Availability
- High