CuraSec

Act active

SAP Patches CVSS 10.0 Unauthenticated RCE in Extended Passport Processing

  • Engineer — Act: A public PoC on GitHub for a CVSS 10.0 unauthenticated memory-corruption RCE in SAP EPP meets the Act bar even without KEV listing. Apply SAP’s September 2026 security patch for CVE-2026-44756 immediately if you run SAP Extended Passport Processing.
  • SOC/IR — Plan: No active exploitation observed (EPSS 0.00, no KEV), but a public PoC raises the likelihood of imminent attempts; build or tune detections for anomalous unauthenticated requests targeting SAP EPP endpoints before exploitation materializes.
  • Leader — Plan: A maximum-severity publicly-PoC’d RCE in SAP — widely deployed in enterprise environments — warrants confirming this quarter whether your organization runs SAP EPP and ensuring the engineering team has this patch scheduled in their current sprint.
  • Signals: CVE-2026-44756 — CISA KEV: not listed, EPSS 0.00, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.