Onapsis

Onapsis

Share

Protecting the business-critical applications that power the global economy

Onapsis protects the business-critical applications that power the global economy including ERP, CRM, PLM, HCM, SCM and BI applications from SAP®, Oracle® and leading SaaS providers. Onapsis proudly serves more than 300 of the world’s leading brands including 20% of the Fortune 100 and partners with leading consulting and audit firms such as Accenture, Deloitte, IBM, PwC and Verizon. The Onapsis Research Labs is responsible for the discovery and mitigation of more than 800 zero-day business-critical application vulnerabilities.

09/23/2026

An open-source exploitation toolkit named "SAPMAP" was released on September 15th. It contains public proof-of-concept exploits targeting critical SAP vulnerabilities, including several patched earlier this month.

Onapsis CTO JP Perez-Etchegoyen published a technical breakdown of what's inside the toolkit and how security teams can protect their landscapes before these exploits are weaponized.

Key details covered in the analysis:

- Active payloads and capabilities inside SAPMAP
- How to check your SAP landscape for toolkit activity
- Steps to prioritize patches and mitigate exposure

Read the full technical analysis here: https://bit.ly/46G1K9r

Photos from Onapsis's post 09/23/2026

As organizations accelerate their cloud migration and integrate AI into enterprise workloads, securing SAP environments has never been more critical. 🔒🤖

The latest SAPinsider Research Report, Cloud and AI Security for SAP, dives into how SAP customers are navigating the intersection of cloud expansion and AI security, ensuring expanding footprints are protected while defending against emerging threats.

Key takeaways include:
🔹 How security strategies are evolving with cloud adoption
🔹 The dual impact of AI in SAP security (enhancing protection vs. new attack surfaces)
🔹 Practical steps for safeguarding cloud-based enterprise systems

Check out the key takeaways below and access the full report in the comments!

September 2026 | Top SAP Security News from Onapsis 09/23/2026

September has been one of the most active months for SAP security this year, let's talk about it.

This month has been packed with SAP news requiring immediate action:
🛠️ SAPMAP exploitation toolkit released Sept. 16
⚠️ OVERPASS & S4GET vulnerabilities that leave enterprise business data exposed across web, SAP GUI, and RFC layers
ℹ️ September's Patch day updates (Onapsis Research Labs is responsible for finding 75% of all SAPHotNews for this month.)

Check out this arsenal of content set to equip you with the sharpest intelligence and strongest of defenses.

Link in comments below. Subscribe and we'll send you next month's edition directly!

September 2026 | Top SAP Security News from Onapsis It’s been an active month in SAP security. Following September’s Patch Tuesday, the release of an open-source SAP exploitation toolkit (SAPMAP) has heightened the risk landscape especially around critical vulnerabilities recently uncovered by Onapsis Research Labs.

09/22/2026

Were you able to catch us live yesterday for our threat advisory? With last week's release of the SAPMAP toolkit, we wanted to arm the community with knowledge ASAP. 🧠⚡

As always, the session is now available on-demand for those who weren't able to attend so you don't have to miss out on any of it.

Our CTO Juan-Perez Etchegoyen walks you through each piece of the toolkit and the recommended approaches that executive and security leadership should follow.

Consider this your guide straight from the team that's partenered with SAP to discover and help mitigate 1,000+ zero-days.

Link to watch is in the comments below!

09/21/2026

Last call to join our live discussion on the new SAPMAP exploitation kit!

Open-source PoCs for critical SAP vulnerabilities are now public, raising the risk level across enterprise landscapes.

At 10 a.m. EDT Juan Perez-Etchegoyen is unpacking the toolkit and sharing his expertise on how to leverage the latest threat insights to keep your defenses strong. 💪

Don't miss out 🔗 https://bit.ly/4rbDyoG

Photos from Onapsis's post 09/18/2026

Let's get loud for our newest group of Onas! 👏📣

Please join us in giving a warm welcome to our newest team members across Legal, Sales, SRE, Software Engineering, and Technical Support.

We're thrilled to have you on board and excited to grow together! Drop a welcome message in the comments below. 👇✨

09/17/2026

Critical SAP kernel vulnerabilities. A newly released exploitation toolkit. 75% of this month's HotNews Notes uncovered by our team.

September has been one of the most active months for SAP security this year and staying ahead of these threats requires immediate action.

In the latest edition of Defenders Monthly, we break down:
🟠 SAPMAP Toolkit Advisory: What public PoC exploits mean for your landscape
🟠 Deep Dives: Key takeaways & remediation strategies for OVERPASS (CVE-2026-44756) and S4GET (CVE-2026-58240)
🟠 Exclusive Briefing: Details on our upcoming live walkthrough with Onapsis CTO Juan Perez-Etchegoyen

Don't let new threat toolkits catch your environment off guard.

📖 Read this month's full newsletter and subscribe below.
https://bit.ly/4y8npmY

Photos from Onapsis's post 09/16/2026

The open-source SAPMAP toolkit is now public.

SAPMAP brings automated exploitation capabilities and PoCs for critical SAP vulnerabilities, raising the risk level for SAP environments.

If you manage SAP systems, here is what you need to prioritize immediately:
1️⃣ Patch critical OVERPASS and S4GET vulnerabilities right away.
2️⃣ Assess your SAP assets to identify systems exposed to SAPMAP’s exploit coverage.
3️⃣ Deploy SAP-specific threat monitoring to catch early signs of exploitation.

Want a deeper look at the toolkit and actionable defense strategies? Join our upcoming live threat briefing with Juan Perez-Etchegoyen (CTO & Head of Onapsis Research Labs).

🗓️ Date: Monday, September 21, 2026
⏰ Time: 10:00 AM EDT

Register in the comments below today to secure your spot 👇

09/15/2026

🚨 New SAP Threat Advisory: A New SAP Exploitation Kit Has Been Released

Following the latest SAP Patch Day, an open-source offensive toolkit dubbed SAPMAP was publicly released today. This toolkit contains multiple exploits and offensive security capabilities for SAP systems, including proof-of-concept (PoC) exploits for critical vulnerabilities that the Onapsis Research Labs discovered and helped SAP patch last week.

While active in-the-wild exploitation hasn't been detected yet, history shows that public exploit PoCs can be leveraged by threat actors to trigger widespread attacks within days or weeks. Onapsis continues to monitor our Global SAP Threat Intel Network for threat activity.

Join Onapsis CTO Juan Perez-Etchegoyen for an exclusive threat briefing on Monday, September 21, 2026, at 10 AM EST to unpack what’s inside the toolkit and how to safeguard your SAP landscape before threat actors move in.

Reserve your spot here 👉 https://bit.ly/4rbDyoG

09/14/2026

Is your SAP landscape protected against the latest critical vulnerabilities?

SAP's September Patch Tuesday introduced critical HotNews security notes, including unauthenticated CVSS 10.0 flaws (OVERPASS & S4GET) that leave enterprise business data vulnerable across web, SAP GUI, and RFC layers.

Catch our on-demand joint session with experts from Onapsis and SAP to get actionable guidance on securing your environments.

What you’ll learn:
🔷 Key Vulnerabilities: High-level breakdowns of OVERPASS (CVE-2026-44756) and S4GET (CVE-2026-58240).
🔷 Attack Surface & Impact: How unauthenticated remotely exploitable threats put critical business data at risk.
🔷 Remediation & Mitigation Strategy: Step-by-step steps to patch and safeguard your landscape immediately.

Speakers include Juan Pablo Perez-Etchegoyen (CTO, Onapsis) and Jay Thoden van Velzen (Technical Advisor, SAP).

Watch the session on demand here: https://bit.ly/4j3jQJO

Want your business to be the top-listed Computer & Electronics Service in Boston?
Click here to claim your Sponsored Listing.

Address


Boston, MA