SAP releases security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing. The issue is described as a kernel-level problem that can be triggered by an unauthenticated, remote attacker.
According to reporting across outlets, the vulnerability is tracked as CVE-2026-44756 with a CVSS score of 10.0. SecurityWeek describes the flaw as enabling outcomes such as arbitrary command execution, access to protected information or secrets, and modification of data. The Hacker News characterizes the underlying technical cause as memory corruption.
Both sources attribute discovery and reporting to SAP. While the outlets emphasize similar potential impacts and the same high severity rating, they differ mainly in how they frame the technical description (e.g., memory corruption versus broader exploitation consequences).