On Demand

Watch Onapsis and SAP talk through September’s Vulnerabilities.
On September Patch Tuesday, SAP patched multiple HotNews, including critical vulnerabilities that are remotely exploitable without credentials. Watch Onapsis and SAP in this joint webinar where we will provide guidance to organizations on the latest patches released by SAP, including the critical vulnerabilities CVE-2026-44756 and CVE-2026-58240.
We will go over the SAP Security Notes and the immediate remediation steps required to shield your SAP landscape from exploitation.
Key Takeaways :
- Understand OVERPASS (CVE-2026-44756) and S4GET (CVE-2026-58240): A high level overview of these critical vulnerabilities.
- Impact & Attack Surface: Why an unauthenticated CVSS 10.0 flaw reachable across multiple SAP components and protocols poses an immediate threat to underlying business data.
- Remediation & Mitigation Strategy: Step-by-step guidance on applying patches and protective measures to secure web, SAP GUI, and RFC layers.
- Read our full SAP Patch Day: September 2026 here
The Onapsis Research Labs goes over a threat advisory on the newly released SAPMAP Exploitation Toolkit containing the latest threat insights and protection guidance. This toolkit contains multiple exploits and offensive security capabilities for SAP systems, including proof-of-concept (PoC) exploits for critical vulnerabilities OVERPASS and S4GET (which Onapsis discovered and helped SAP patch just weeks ago). Watch the on demand webinar here.

