Security news

Latest security news

8 of 1,256 storiesSAPClear all

Today · Wed, 16 Sept 2026

  1. Microsoft says Copilot buttons still missing in classic Outlook

    Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users.

    BleepingComputerMicrosoft, Windows, Outlook

Thu, 10 Sept 2026

  1. 2026-011: Critical Vulnerabilities in SAP Kernel and NetWeaver Message Server

    On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication check in the SAP NetWeaver Message Server[6]. Both are remotely exploitable without authentication. According to the reporting researchers, successful exploitation of either can result in arbitrary operating system command execution under the account that owns the SAP installation, leading to full compromise of the affected system and the business data it holds[6]. CERT-EU strongly recommends applying SAP Security Notes 3747649 and 3759472 as soon as possible.

    CERT-EUSAP

Wed, 9 Sept 2026

  1. SAP Patches Maximum Severity “Overpass” Flaw

    Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0

    Infosecurity MagazineSAP
  2. SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

    The Hacker NewsSAP

Tue, 8 Sept 2026

  1. SAP security advisory – September 2026 monthly rollup (AV26-894)

    Serial Number: AV26-894 Date: September 8, 2026 As of September 8, 2026, SAP_SE is affected by vulnerabilities in the following products: SAP Extended Passport (EPP) Processing – KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, 9.18, 9.19, 9.20, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 SAP NetWeaver (Message Server) - versions KERNEL 9.16, 9.18, 9.19, and 9.20 SAP Cloud Application Programming Model (CAP) prior or equal to 1.183 prior or equal to 2.7.6 prior or equal to 3.9.6 prior or equal to 4.0.2 SAP NetWeaver (SAP GUI for Java) - version BC-FES-JAV 8.10 SAP Integration Suite Version Cloud Integration - Trading Partner Management V2 2.9.2, Version B2B Integration Factory - Cloud Integration - Trading Partner Management 1.10.0 SAP NetWeaver Business Client – versions BC-WD-CLT-BUS 8.00 and 8.10 SAP NetWeaver Application Server for ABAP and ABAP Platform – versions KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 7.53, 8.04, KERNEL 7.22, 7.53, 7.54, 7.77, 7.93, 8.04, 9.16, 9.18, 9.19 and 9.20 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become

    Canadian Centre for Cyber SecuritySAP
  2. SAP warns of maximum severity 'OVERPASS' kernel vulnerability

    SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.

    BleepingComputerSAP

Thu, 27 Aug 2026

  1. Russian Hackers Phish EU Officials Over Messaging Apps

    EU governments are trying to move away from popular messaging apps as nation-state threat groups shift their focus from email to Signal and WhatsApp.

    Dark Reading

Tue, 4 Aug 2026

  1. WhatsApp Scam Hijacks Accounts via Linked Devices Feature

    WhatsApp scam abused the Linked devices feature to hijack accounts without stealing any passwords

    Infosecurity Magazine

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets