Skip to content
SAPCVE-2026-44756

SAP Extended Passport (EPP) Processing: buffer overflow

Critical10.0CVE-2026-44756 · Published Sep 8, 2026 · updated Sep 22, 2026

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

SAP advisory

Affected versions

PackageAffectedFixed in
SAP Extended Passport (EPP) Processing
Product
<= KRNL64NUC 7.22No fix yet
<= 7.22EXTNo fix yet
<= KRNL64UC 7.22No fix yet
<= 7.53No fix yet
Details and references

More SAP advisories

All SAP
Advisory
SAP NetWeaver and ABAP Platform: missing authorization
Medium4.3Sep 8
SAP NetWeaver Business Client: code execution
High7.8Sep 8
SAP Web Dispatcher, Internet: information disclosure
Medium6.5Sep 8
SAP Cloud Application Programming Model (CAP): weakly protected credentials
Critical9.4Sep 8
SAP Manufacturing Integration and Intelligence: server-side request forgery
Medium6.5Sep 8
SAP UI5 does not sufficiently validate the parent frame's origin against the...
Medium4.3Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.