{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/erp/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:epp_library:epp_processing_library:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":10,"id":"CVE-2026-44756"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Extended Passport Protocol (EPP) processing library","S/4HANA","ERP","Business Suite (ECC)","NetWeaver","Web Dispatcher","BW/4HANA","Enterprise Portal","PI/PO","Solution Manager","ABAP Developer Tools","Integration Suite","NetWeaver Business Client","Commerce Cloud"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["SAP"],"content_html":"\u003cp\u003eCVE-2026-44756 describes a critical memory safety vulnerability discovered within the Extended Passport Protocol (EPP) processing library. This flaw permits an unauthenticated attacker to supply a specifically crafted network request containing a malformed EPP header. When processed by the library, this malformed input can lead to undefined memory behavior and abnormal program termination. Given the nature of memory corruption vulnerabilities in protocol parsers, this issue poses a significant risk to the confidentiality, integrity, and availability of any infrastructure or application utilizing this library. The CVSS base score of 10.0 reflects the critical potential for remote exploitation and total system impact. Defenders should prioritize identifying systems using this library and applying updates as they become available from their respective software vendors.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in service disruption via application crashes and carries the potential for arbitrary code execution. Organizations running public-facing services that utilize the EPP parsing library are at the highest risk, as they are exposed to unauthenticated exploitation attempts over the network.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eIdentify all internal and external-facing applications that incorporate the Extended Passport Protocol (EPP) processing library. Monitor network traffic logs for malformed or unusually large EPP protocol headers that may indicate exploitation attempts. Patch all instances of the EPP library to the latest vendor-supplied version as soon as updates are released to address the underlying memory safety flaw.\u003c/p\u003e\n","date_modified":"2026-09-08T15:49:34Z","date_published":"2026-09-08T01:37:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-44756/","summary":"An unauthenticated remote code execution vulnerability (CVE-2026-44756) in the Extended Passport Protocol library allows attackers to trigger crashes or potentially execute code via malformed network headers.","title":"Memory Safety Vulnerability in Extended Passport Protocol Library","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-44756/"}],"language":"en","title":"CraftedSignal Threat Feed - ERP","version":"https://jsonfeed.org/version/1.1"}