Posts Tagged ‘ERP’
SAP Kernel RCE Vulnerability Hits 10,000+ Systems
A maximum-severity SAP kernel RCE vulnerability, tracked as CVE-2026-44756 and named OVERPASS by Onapsis Research Labs, lets an unauthenticated attacker reach shared SAP kernel code before any session authenticates — and it is reachable over three separate protocol paths at once. SAP patched the CVSS 10.0 flaw on September 8, 2026, as part of its…
Read MoreSAP Commerce Cloud CVE-2026-58231: CVSS 10.0 RCE
SAP Commerce Cloud CVE-2026-58231, a maximum-severity (CVSS 10.0) flaw disclosed on SAP’s August 2026 Security Patch Day, lets an unauthenticated attacker with network access reach the Data Hub import endpoint and potentially execute arbitrary code — no login, no user interaction, just a crafted request to a component many DACH e-commerce and manufacturing storefronts run…
Read MoreOracle E-Business Suite CVE-2026-46817 Actively Exploited
Oracle E-Business Suite CVE-2026-46817, a critical flaw, is under active exploitation: an unauthenticated attacker with nothing more than HTTP access can take over Oracle Payments — the module that executes your payment runs. CISA added the flaw to its Known Exploited Vulnerabilities catalog on July 15 and gave US federal agencies three days to fix…
Read More
