Vulnerability Intelligence Report
Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing
CVE-2026-44756
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Memory Corruption
No Active Exploit Signals
CVSS Base Score
10.0
CRITICAL
Exploitability:3.9
Impact Score:6.1
EPSS Probability:0.32%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-120 ↗CWE-120: Buffer Copy without Checking Size of Input
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| SAP_SE | SAP Extended Passport (EPP) Processing | KRNL64NUC 7.22 (affected), 7.22EXT (affected), KRNL64UC 7.22 (affected), 7.53 (affected), 8.04 (affected), WEBDISP 9.16 (affected), 9.18 (affected), 9.19 (affected), 9.20 (affected), KERNEL 7.22 (affected), 7.54 (affected), 7.77 (affected), 7.89 (affected), 7.93 (affected), 9.16 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | SAP SE · Vendor · Germany |
| Reserved | 2026-05-07T18:31:04 |
| Published | 2026-09-08T00:10:16 |
| Last Updated | 2026-09-08T12:42:17 |
Community Chatter & Buzz