Skip to content
Threat Feed
critical advisory updated

Memory Safety Vulnerability in Extended Passport Protocol Library

An unauthenticated remote code execution vulnerability (CVE-2026-44756) in the Extended Passport Protocol library allows attackers to trigger crashes or potentially execute code via malformed network headers.

CVE search metadata

CVE search record: CVE-2026-44756. Severity: critical. CVSS: 10.0. KEV: no. Product: Extended Passport Protocol (EPP) processing library, S/4HANA, ERP, Business Suite (ECC), NetWeaver, Web Dispatcher, BW/4HANA, Enterprise Portal, PI/PO, Solution Manager, ABAP Developer Tools, Integration Suite, NetWeaver Business Client, Commerce Cloud. Brief: Memory Safety Vulnerability in Extended Passport Protocol Library. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-44756/

What's new

CVE-2026-44756 describes a critical memory safety vulnerability discovered within the Extended Passport Protocol (EPP) processing library. This flaw permits an unauthenticated attacker to supply a specifically crafted network request containing a malformed EPP header. When processed by the library, this malformed input can lead to undefined memory behavior and abnormal program termination. Given the nature of memory corruption vulnerabilities in protocol parsers, this issue poses a significant risk to the confidentiality, integrity, and availability of any infrastructure or application utilizing this library. The CVSS base score of 10.0 reflects the critical potential for remote exploitation and total system impact. Defenders should prioritize identifying systems using this library and applying updates as they become available from their respective software vendors.

Impact

Successful exploitation of this vulnerability results in service disruption via application crashes and carries the potential for arbitrary code execution. Organizations running public-facing services that utilize the EPP parsing library are at the highest risk, as they are exposed to unauthenticated exploitation attempts over the network.

Recommendation

Identify all internal and external-facing applications that incorporate the Extended Passport Protocol (EPP) processing library. Monitor network traffic logs for malformed or unusually large EPP protocol headers that may indicate exploitation attempts. Patch all instances of the EPP library to the latest vendor-supplied version as soon as updates are released to address the underlying memory safety flaw.


Immediate actions

Inventory all applications leveraging the EPP processing library.

IT Operations 48h

Monitor network traffic for anomalous EPP header structures.

SOC 24h

Mitigations

Upgrade EPP processing library to the secure version provided by the vendor.

immediate IT Operations

CVE-2026-44756