# CVE-2026-44756

## Summary

- **CVE ID:** CVE-2026-44756
- **Severity:** CRITICAL
- **CVSS Score:** 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- **CWE:** CWE-120
- **Published:** Sep 8, 2026
- **Last Modified:** Sep 8, 2026

## Description

A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.

## Affected Products

- SAP_SE — SAP Extended Passport (EPP) Processing (KRNL64NUC 7.22)
- SAP_SE — SAP Extended Passport (EPP) Processing (7.22EXT)
- SAP_SE — SAP Extended Passport (EPP) Processing (KRNL64UC 7.22)
- SAP_SE — SAP Extended Passport (EPP) Processing (7.53)
- SAP_SE — SAP Extended Passport (EPP) Processing (8.04)
- SAP_SE — SAP Extended Passport (EPP) Processing (WEBDISP 9.16)
- SAP_SE — SAP Extended Passport (EPP) Processing (9.18)
- SAP_SE — SAP Extended Passport (EPP) Processing (9.19)
- SAP_SE — SAP Extended Passport (EPP) Processing (9.20)
- SAP_SE — SAP Extended Passport (EPP) Processing (KERNEL 7.22)
- SAP_SE — SAP Extended Passport (EPP) Processing (7.54)
- SAP_SE — SAP Extended Passport (EPP) Processing (7.77)
- SAP_SE — SAP Extended Passport (EPP) Processing (7.89)
- SAP_SE — SAP Extended Passport (EPP) Processing (7.93)
- SAP_SE — SAP Extended Passport (EPP) Processing (9.16)

## References

- [CNA](https://me.sap.com/notes/3747649)
- [CNA](https://url.sap/sapsecuritypatchday)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.32%
- **EPSS Percentile:** 24.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._