LATEST View all updates

SAPMAP Exploitation Toolkit: OVERPASS, S4GET PoCs and What SAP Teams Should Patch

SAPMAP packages public SAP exploit capability, including OVERPASS and S4GET PoCs, raising patch-validation urgency.

Cybersecurity illustration showing multiple public exploit paths targeting enterprise SAP-style systems with patch barriers

Signal Brief

  • SAPMAP is a public exploitation toolkit, not a new vulnerability; it packages multiple SAP attack capabilities and known exploit paths.
  • OVERPASS CVE-2026-44756 and S4GET CVE-2026-58240 are already patched through SAP Security Notes 3747649 and 3759472.
  • Fixing only OVERPASS and S4GET does not address every SAPMAP module because the toolkit also covers older SAP vulnerabilities.
  • Onapsis said it had not observed active threat-actor use of SAPMAP as of its September 21 briefing.

The SAPMAP exploitation toolkit is now publicly available and packages multiple SAP discovery and exploitation capabilities into one framework, including public proof-of-concept coverage for the recently patched OVERPASS and S4GET vulnerabilities. The immediate defender question is not whether SAPMAP creates new vulnerabilities. It does not. The risk is that public tooling can make known weaknesses easier to identify and exploit on SAP systems that remain exposed or unpatched.

Current answer: SAP has already released fixes for OVERPASS, tracked as CVE-2026-44756 under SAP Security Note 3747649, and S4GET, tracked as CVE-2026-58240 under SAP Security Note 3759472. SAP teams should verify those fixes where applicable, but should not stop there because SAPMAP includes additional older exploit paths. Onapsis said it had not observed active threat-actor use of SAPMAP as of its September 21 threat briefing.

What changed with SAPMAP?

The important information-state change is the public availability of a SAP-focused exploitation framework. Onapsis Research Labs describes SAPMAP as combining SAP discovery, exploit modules, post-authentication capabilities, privilege-related techniques, attack-path automation and other offensive functions in one toolkit.

That lowers the effort required to move from knowing that a SAP vulnerability exists to testing whether a reachable SAP environment still exposes a known weakness. Public tooling does not make a patched system vulnerable again, but it increases the importance of verifying that patches and exposure controls are actually in place.

SAPMAP defensive decision path showing toolkit exposure, vulnerability mapping, SAP Security Note checks and monitoring
SAP teams should map public toolkit capability to their own exposed components and verify the controlling SAP Security Notes.

Is SAPMAP itself a new SAP vulnerability?

No. SAPMAP is tooling, not a newly discovered vulnerability. Its modules target known SAP weaknesses and attack paths. Some of those flaws are recent, including OVERPASS and S4GET, while other exploit families mapped by Onapsis involve much older SAP vulnerabilities.

This distinction matters because the correct response is not to search for a single universal “SAPMAP patch.” Administrators need to determine which toolkit-covered vulnerabilities and services exist in their own landscape and then verify the controlling SAP Security Notes and product-specific remediation.

Does SAPMAP include pre-authentication exploit capability?

Yes. In the repository snapshot analyzed by Onapsis, the researchers counted multiple standalone pre-authentication exploit files. Pre-authentication matters because those paths do not depend on an attacker first obtaining normal SAP application credentials when the underlying vulnerable component is reachable and unpatched.

That does not mean every SAP system is remotely exploitable by SAPMAP. Each exploit has its own affected products, versions, prerequisites and exposure conditions.

OVERPASS: what SAP teams need to verify

OVERPASS is tracked as CVE-2026-44756. SAP’s September 2026 Patch Day lists the issue as Critical with a CVSS score of 10.0 and points administrators to SAP Security Note 3747649.

Onapsis says SAPMAP repository history included a public proof of concept for OVERPASS. That means organizations should treat patch verification as an immediate operational task rather than assuming the existence of a September patch automatically proves every relevant SAP system has received it.

S4GET: what SAP teams need to verify

S4GET is tracked as CVE-2026-58240. SAP lists it as Critical with a CVSS score of 9.8 and directs customers to SAP Security Note 3759472.

CERT-EU also highlighted both S4GET and OVERPASS as remotely exploitable without authentication in affected vulnerable configurations and urged organizations to apply the applicable SAP fixes promptly.

Does patching OVERPASS and S4GET remove all SAPMAP risk?

No. Those two September vulnerabilities are particularly important because their public exploit availability is recent, but SAPMAP contains a broader set of offensive modules. Onapsis mapped additional pre-authentication exploit coverage to older SAP weaknesses and defensive SAP Notes.

Teams that verify only CVE-2026-44756 and CVE-2026-58240 can therefore miss older exposed paths that the toolkit also knows how to test.

How should SAP administrators verify their exposure?

1. Inventory reachable SAP systems.

Include production, non-production, forgotten and shadow environments. Public exploit tooling is most useful to an attacker when an exposed system has not been included in normal patch governance.

2. Check the September critical fixes.

Verify whether SAP Security Notes 3747649 and 3759472 apply to the installed products and whether the required remediation has actually been implemented.

3. Review older toolkit-covered vulnerabilities.

Do not treat OVERPASS and S4GET as the complete SAPMAP attack surface. Map the organization’s SAP products and versions against other exploit families identified by the research.

4. Prioritize externally reachable services.

Internet-reachable or otherwise broadly accessible SAP interfaces deserve faster validation because pre-authentication paths can reduce the attacker’s initial requirements.

5. Monitor the SAP application layer.

Use existing SAP security monitoring, logging, SOC tooling and incident-response controls to investigate suspicious authentication, administrative, code-execution or configuration activity relevant to the organization’s environment.

Which other exploit families are relevant?

Onapsis mapped SAPMAP coverage across several previously known SAP exploit families, including older pre-authentication issues as well as the new OVERPASS and S4GET modules. The exact relevance of each module depends on the SAP products, versions and services deployed in a specific environment.

TPS is intentionally not reproducing exploit commands, module invocation syntax, payload construction or attack automation instructions. The useful defender task is mapping known exploit coverage to vulnerable assets and controlling SAP Security Notes.

Is SAPMAP already being used by threat actors?

Onapsis said during its September 21 threat briefing that it had not observed active threat-actor exploitation using SAPMAP at that time. That is an important evidence boundary: public exploit tooling increases attack readiness, but public availability alone is not proof of malicious use in real-world intrusions.

This state can change quickly. First confirmed malicious use, exploitation telemetry, indicators of compromise or a national CERT escalation would materially change the urgency and should update this same article.

What does SAPMAP change for defenders?

The toolkit increases the operational value of old and new SAP vulnerabilities to attackers by bringing discovery and exploitation functions together. That increases the cost of leaving even older SAP weaknesses unaddressed on reachable systems.

It also reinforces a broader SAP security problem: patch publication does not equal patch deployment. A vulnerability can remain operationally useful to attackers long after SAP has issued a Security Note if organizations have not identified the exposed system, applied the fix or reduced unnecessary reachability.

What SAPMAP does not prove

SAPMAP does not prove that every SAP landscape is vulnerable, that properly patched systems remain exploitable, or that attackers are currently using the toolkit in active campaigns. It also does not turn the September vulnerabilities back into zero-days after SAP has published fixes.

Readers should therefore avoid two extremes: dismissing SAPMAP because the CVEs are already patched, or treating the toolkit’s public release as proof that all SAP environments are under active attack.

What could change next?

The most important next developments are confirmed malicious SAPMAP use, new toolkit exploit modules, Onapsis or SAP indicators and detection guidance, additional CERT or CISA escalation, new exploitation telemetry and changes to relevant SAP Security Notes.

Those are same-canonical lifecycle changes. They should update this page unless they create a materially different reader problem such as compromise detection, incident containment or recovery after confirmed exploitation.

Verification note

TPS reviewed Onapsis Research Labs’ SAPMAP analysis and September 21 threat briefing, SAP’s September 2026 Security Patch Day information, CERT-EU guidance and current SAPMAP-related defensive reporting. The public toolkit state, OVERPASS and S4GET mapping, and corresponding SAP Security Notes are supported by direct or authoritative sources. Active threat-actor use of SAPMAP was not observed by Onapsis at the latest reviewed briefing.

Bottom line: SAPMAP matters because public exploitation tooling now brings multiple SAP attack paths into one framework. SAP teams should verify the September critical patches for OVERPASS and S4GET, then extend that review to older toolkit-covered weaknesses rather than assuming those two fixes alone eliminate SAPMAP exposure.

Public provenanceVerification & change history

This log separates publication, substantive reader-facing updates and source-verification checks. Older maintenance activity may predate detailed public logging.

  1. Verified

    TPS completed a source-verification pass.

  2. Published

    Article first published.

Trust boundary

Disclaimer

ThePulseSignal (TPS) provides this evidence-led article for informational and editorial guidance. SAPMAP is a public exploitation toolkit, but reviewed evidence does not establish active threat-actor use of SAPMAP as of the September 21 Onapsis briefing. Individual SAPMAP modules apply only where the underlying vulnerable SAP component or configuration is exposed. Verify current SAP Security Notes, Onapsis research and other controlling current guidance before consequential remediation or incident-response action.