{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/sap-kernel/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["SAP Kernel"],"_cs_severities":["high"],"_cs_tags":["sap","rce","kernel","vulnerability"],"_cs_type":"advisory","_cs_vendors":["SAP"],"content_html":"\u003cp\u003eResearchers have identified a critical vulnerability within SAP Extended Passport (EPP) processing, a core kernel mechanism utilized across the SAP ecosystem for tracing and monitoring end-to-end communication. EPP data structures are generated automatically upon the initiation of user sessions and traverse distributed landscapes via communication protocols including RFC (Remote Function Call) and HTTP. Because this EPP processing logic is embedded within the SAP Kernel, the vulnerability is accessible to unauthenticated attackers through the SAP GUI layer or via inter-system RFC links. This allows for remote exploitation without prior authentication. Successful execution leads to the compromise of the underlying SAP host, as the attacker gains the ability to run arbitrary operating system commands with SAP administrative privileges. This vulnerability affects a broad range of SAP components and poses a significant risk of total data and process compromise for organizations running affected SAP environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an unauthenticated remote attacker to achieve full system compromise. By gaining the ability to execute arbitrary OS commands with administrative privileges, an attacker can exfiltrate sensitive business data, manipulate core enterprise processes, and pivot deeper into the target organization's internal network. This threat is particularly critical due to the ubiquitous nature of the affected SAP Kernel code across both SAP and non-SAP interconnected landscapes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification of internet-facing SAP components. Monitor SAP logs for anomalous RFC and HTTP traffic patterns originating from unauthorized or external network ranges. Engage with SAP support to obtain and apply the necessary kernel patches to address the EPP processing vulnerability.\u003c/p\u003e\n","date_modified":"2026-09-11T00:57:44Z","date_published":"2026-09-11T00:57:44Z","id":"https://feed.craftedsignal.io/briefs/2026-09-sap-epp-rce/","summary":"A critical unauthenticated remote code execution vulnerability in the SAP Extended Passport (EPP) kernel component allows attackers to execute arbitrary system commands via RFC or HTTP communication layers.","title":"Remote Code Execution Vulnerability in SAP Extended Passport Processing","url":"https://feed.craftedsignal.io/briefs/2026-09-sap-epp-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - SAP Kernel","version":"https://jsonfeed.org/version/1.1"}