SAP מתקנת פגיעות חמורה בציון CVSS 10.0 ב-Kernel, המאפשרת RCE ללא אימות
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

◆ סיכום AI
SAP הוציאה עדכוני אבטחה לטיפול במספר פגיעויות, כולל פגם קריטי ב-SAP Extended Passport (EPP) Processing עם ציון CVSS 10.0. פגיעות מסוג memory corruption זו, המסומנת כ-CVE-2026-44756, מאפשרת הרצת קוד מרחוק (RCE) ללא צורך באימות. היא טומנת בחובה סיכון גבוה לסודיות, שלמות וזמינות היישום.
# מהמקור
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP