Skip to content
tag — unauthenticated-rce

grep -rl "unauthenticated-rce" ./articles

#unauthenticated-rce

2 articles

The SAP flaw runs before authentication, so Segregation of Duties does not apply

2026-09-09Security

CVE-2026-44756 is a CVSS 10.0 memory corruption bug in the SAP kernel's Extended Passport handling, reachable with a single malformed header. Onapsis puts the consequence plainly: SAP authorizations and Segregation of Duties will not help, because the vulnerable code runs before any authentication step.

N-able's two documents disagreed about exploitation. CISA has settled it

2026-09-07Security

CVE-2026-86218 is a CVSS 10.0 pre-authentication RCE in N-central, patched in the fourth hotfix in five weeks. For two days the vendor's release notes and its incident notice said opposite things about whether it was being exploited. CISA added it to the KEV catalogue on 8 September with a three-day federal deadline.