CVE 9.8 CRITICAL

Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform_CVE-2026-27671

9.8 / 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.

AI Analysis

Memory corruption vulnerability due to improper RFC protocol validation in SAP Kernel used by Application Server ABAP, allowing unauthenticated attackers to send crafted RFC requests and potentially impact confidentiality, integrity, and availability

Basic Information

ID CVE-2026-27671
Source sap
Published Jun 9, 2026 at 00:20

Affected Product

Vendor SAP_SE
Product SAP NetWeaver and ABAP Platform
Version KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 722EXT, 7.53, KERNEL 7.22, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 91.9
Affected Versions SAP_SE SAP NetWeaver and ABAP Platform KRNL64NUC 7.22
SAP_SE SAP NetWeaver and ABAP Platform 7.22EXT
SAP_SE SAP NetWeaver and ABAP Platform KRNL64UC 7.22
SAP_SE SAP NetWeaver and ABAP Platform 722EXT
SAP_SE SAP NetWeaver and ABAP Platform 7.53
SAP_SE SAP NetWeaver and ABAP Platform KERNEL 7.22
SAP_SE SAP NetWeaver and ABAP Platform 7.54
SAP_SE SAP NetWeaver and ABAP Platform 7.77
SAP_SE SAP NetWeaver and ABAP Platform 7.89
SAP_SE SAP NetWeaver and ABAP Platform 7.93
SAP_SE SAP NetWeaver and ABAP Platform 9.16
SAP_SE SAP NetWeaver and ABAP Platform 9.18
SAP_SE SAP NetWeaver and ABAP Platform 91.9

CWE Classification

AI Assessment

AI Score 9.8 / 10
AI Severity Critical
Vendor SAP
Product SAP NetWeaver and ABAP Platform
Version 7.22, 7.22EXT, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 91.9

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.