Onapsis Research Labs Threat Advisory: Unpacking the SAPMAP Exploitation Toolkit with Latest Threat Insights and Protection Guidance

10 AM EST

September 21, 2026

Following the SAP September 2026 Patch Day, a new open-source SAP exploitation toolkit (dubbed SAPMAP) was released on September 15, 2026. This toolkit contains multiple exploits and offensive security capabilities for SAP systems, including proof-of-concept (PoC) exploits for critical vulnerabilities OVERPASS and S4GET (which Onapsis discovered and helped SAP patch just weeks ago).   

While the Onapsis Research Labs have not observed active exploitation using this toolkit by threat actors yet, historical trends (such as the critical SAP zero-day CVE-2025-31324) demonstrate that public PoC releases frequently jumpstart attack campaigns within days or weeks. 

Join JP Perez-Etchegoyen, CTO and Head of the Onapsis Research Labs, on Monday, September 21, 2026, for an in-depth threat breakdown of this exploitation toolkit and what it means to your critical SAP landscapes moving forward.  In this webinar, JP will review the contents of this publicly-released toolkit, discussing the various exploits and payloads contained therein while outlining immediate mitigation and patch prioritization strategies your team can take to to safeguard your SAP enterprise landscape.

Speakers

Juan Pablo Perez-Etchegoyen

CTO

Onapsis

Ready to eliminate your SAP cyber security blindspot?

Let us show you how simple it can be to protect your business applications.

Contact Us