type: incident ยท created: 2026-09-10 ยท updated: 2026-09-10 ยท tags: [incident, sap, kernel, rce, critical-patch] ยท confidence: reported ยท affected_sectors: [technology, financial-services, government] ยท au_impact: true
SAP released a security update addressing a maximum-severity (CVSS 10.0) "OVERPASS" kernel vulnerability that allows unauthenticated remote code execution, escalating the SAP kernel advisory first flagged in the previous day's digest. The flaw, in the SAP Kernel component, permits an unauthenticated attacker to execute arbitrary code โ the most severe rating SAP issues โ making it highly tractable for automated exploitation. SAP NetWeaver/ABAP stack operators (common in Australian and New Zealand enterprise and government environments) should apply the patch as a priority.
| Attribute | Detail |
|---|---|
| Date | 2026-09-09 |
| Type | Unauthenticated RCE (CVSS 10.0) |
| Component | SAP Kernel |
| Status | Patch released; no confirmed in-the-wild exploitation cited |
| Source | The Hacker News โ Tier 2/4 |