DIRAS TAKE
Urgent: this is a remote, unauthenticated flaw with a maximum CVSS score and no fixes published; immediately reduce network exposure of EPP services and follow vendor guidance to mitigate risk.
What is CVE-2026-44756?
An unauthenticated remote attacker can send a crafted EPP network request to SAP Extended Passport (EPP) Processing and trigger a memory-safety failure that may crash or destabilize the service and impact confidentiality, integrity, and availability. CVE-2026-44756 is a CWE-120 memory safety vulnerability that can be triggered by a malformed EPP header. Affected builds include KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, and 9.18–9.20; the attacker needs only network access and does not require authentication.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Which versions of SAP SAP Extended Passport (EPP) Processing are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| SAP Extended Passport (EPP) Processing | KRNL64NUC 7.22 | |
| 7.x | 7.22EXT | |
| SAP Extended Passport (EPP) Processing | KRNL64UC 7.22 | |
| 7.x | 7.53 | |
| 8.x | 8.04 | |
| SAP Extended Passport (EPP) Processing | WEBDISP 9.16 | |
| 9.x | 9.18 | |
| 9.x | 9.19 | |
| 9.x | 9.20 | |
| SAP Extended Passport (EPP) Processing | KERNEL 7.22 |
Is CVE-2026-44756 being exploited?
There are no public reports of exploitation as of 2026-09-30.
How to fix CVE-2026-44756
- Isolate or block network access to EPP processing endpoints from untrusted networks and the internet.
- Apply any vendor mitigations or configuration guidance from SAP as soon as it is released.
- Monitor EPP service logs and network traffic for malformed EPP headers and abnormal process terminations.
- If feasible, disable the EPP processing service until a vendor patch is available.
Frequently asked questions
Is CVE-2026-44756 being actively exploited?
There are no public reports of exploitation of CVE-2026-44756 as of 2026-09-30.
Which SAP Extended Passport (EPP) Processing versions are affected by CVE-2026-44756?
Affected builds include KRNL64NUC 7.22, KRNL64UC 7.22, KERNEL 7.22, 7.22EXT, 7.53, 8.04, WEBDISP 9.16, and 9.18 through 9.20.
Is there a patch for CVE-2026-44756?
No patch is published for CVE-2026-44756 in the provided facts; the affected entries show no fixed versions.
Does CVE-2026-44756 require authentication?
No; the vulnerability can be triggered by an unauthenticated attacker sending a crafted EPP network request with a malformed header.
References
- nvd.nist.gov/vuln/detail/CVE-2026-44756
- cve.org/CVERecord?id=CVE-2026-44756
- me.sap.com/notes/3747649
- url.sap/sapsecuritypatchday
- All SAP CVEs on CVE Radar
- CVEs published in September 2026