started · updated
SAP and Commvault lead major enterprise cybersecurity developments
Major cybersecurity vulnerabilities and new defensive integrations have been identified in the enterprise software sector. SAP has released security notes addressing a critical stack-buffer-overflow vulnerability known as ‘OVERPASS’ (CVE-2026-44756). Rated with a maximum CVSS score of 10.0, this flaw allows unauthenticated remote code execution across various interfaces, including S/4HANA and NetWeaver. Approximately 29,500 German companies subject to NIS2 regulations or BSI supervision face significant compliance risks if these vulnerabilities are not addressed.
Additionally, the US agency CISA has flagged actively exploited vulnerabilities in MikroTik routers. Meanwhile, Commvault has announced an integration with Google Threat Intelligence. This partnership aims to enhance the Commvault Threat Scan workflow by incorporating global threat data from sources like Mandiant and VirusTotal, allowing organizations to more rapidly identify clean recovery points following a cyberattack.