September 10, 2026
- CERT-EU issued a formal advisory on SAP's two criticals — OVERPASS (CVE-2026-44756, CVSS 10.0, memory corruption in kernel Extended Passport processing, reachable unauthenticated from the web, SAP GUI and RFC layers) and S4GET (CVE-2026-58240, 9.8, missing auth in the NetWeaver Message Server) (CERT-EU; earlier coverage). · Exploited in the Wild
in One Exploit Kit, Four Espionage Crews: BlueMoon Turns Chrome's Patch Gap Into a Shared Weapon