Answer in brief
CVE-2026-44756 records a Unknown severity vulnerability in Memory Corruption vulnerability in SAP Extended Passport (EPP) Processing. The current sources do not mark it as known exploited. The current feed maps SAP_SE/SAP Extended Passport (EPP) Processing (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
A CVSS score is not reported in the current record. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps SAP_SE/SAP Extended Passport (EPP) Processing (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| SAP_SE/SAP Extended Passport (EPP) Processinggeneric | KRNL64NUC 7.22 || 7.22EXT || KRNL64UC 7.22 || 7.53 || 8.04 || WEBDISP 9.16 || 9.18 || 9.19 || 9.20 || KERNEL 7.22 || 7.54 || 7.77 || 7.89 || 7.93 || 9.16 | Not reported |
Published upstream
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Sep 8, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Sep 8, 2026
A memory safety vulnerability exists in the Extended Passport Protocol (EPP) processing library. Under specific conditions, an unauthenticated attacker could exploit a crafted network request containing a malformed EPP header, potentially resulting in undefined behavior and abnormal program termination. Successful exploitation may have a high impact on the confidentiality, integrity, and availability of the application.
Quoted source text, attributed separately from HOL analysis.