Critical SAP Flaw Enables Remote Code Execution
A critical vulnerability in SAP's Extended Passport processing allows unauthenticated attackers to achieve remote code execution.

Organizations using SAP software must urgently patch a maximum-severity vulnerability that enables remote code execution. The flaw, tracked as CVE-2026-44756, exists in SAP's Extended Passport processing code and allows unauthenticated attackers to trigger memory corruption before any login check occurs.
Researchers from Onapsis discovered the bug and named it OVERPASS. Pathlock and nullFaktor researchers confirmed that remote code execution is achievable over HTTP/HTTPS and NGRRC protocols in laboratory testing. The vulnerability touches a broad spectrum of SAP products.
Vulnerability Scope and Urgent Patching
The bug impacts core enterprise systems. SAP is urging emergency patching for all internet-facing systems. Public technical write-ups were released within 48 hours of the patch's availability, which security experts warn significantly lowers the barrier for exploit development.
Affected products include:
WordPress Plugin Fuels Webshell Uploads
Separately, attackers are exploiting a critical file-upload flaw in a popular WordPress plugin. Defiant, a security firm, reports blocking more than 100,000 exploit attempts targeting the WooCommerce Wholesale Lead Capture plugin since the bug was disclosed in February.
The vulnerability lets unauthenticated visitors bypass file-type checks. The plugin erroneously trusts an attacker-supplied list of allowed extensions instead of its own configuration, enabling the upload of PHP webshells. Site owners are advised to update to version 2.0.3.2 immediately and inspect their uploads directories for suspicious PHP files.
AI Coding Agents Vulnerable to Silent Takeover
A novel attack vector threatens AI-powered coding assistants. Researchers at Air's security lab disclosed Plugin4Shell, a zero-click flaw affecting Claude Code, OpenAI Codex, GitHub Copilot, and Gemini CLI.
The vulnerability allows an attacker controlling a plugin's repository to swap a pinned, reviewed commit for malicious code without triggering SHA-pinning checks. Because the affected agents check out a requested commit without verifying what code actually lands, an attacker can name a branch after the pinned hash. Git then resolves to the malicious branch. Background auto-updates can push the compromised version to already-installed plugins without any user interaction.
Anthropic and OpenAI have released fixes for Claude Code and Codex. Microsoft has not yet patched GitHub Copilot. Google stated it will not fix the issue in the deprecated Gemini CLI.
IoT Device Flaws Patched by TP-Link
In other vulnerability news, TP-Link has patched two flaws in its Tapo C200 security camera. OPSWAT researchers found an authentication bypass that lets an attacker on the local network replay a value from the camera's own challenge-response process to gain admin access without a password.
A second bug allows a denial-of-service attack. Sending oversized Wi-Fi credential data during the device onboarding process crashes the camera's HTTPS service. TP-Link fixed both issues, tracked as CVE-2026-15315 and CVE-2026-15316, in firmware version V5_1.4.6 released in August.





