CVE-2026-27671
Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
| Vendor | sap_se |
| Product | sap netweaver as abap and abap platform |
| Published | Jun 9, 2026 |
| Last Updated | Jun 9, 2026 |
Stay Ahead of the Next One
Get instant alerts for sap_se sap netweaver as abap and abap platform
Be the first to know when new critical vulnerabilities affecting sap_se sap netweaver as abap and abap platform are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
SAP_SE / SAP NetWeaver AS ABAP and ABAP Platform
KRNL64NUC 7.22 7.22EXT KRNL64UC 7.22 722EXT 7.53 KERNEL 7.22 7.54 7.77 7.89 7.93 9.16 9.18 91.9