Back to overview

CVE-2026-27671

CRITICAL
9.8
CVSS 3.1
Description
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.

Metadata

CVE ID
CVE-2026-27671
State
PUBLISHED
Assigner
sap
Reserved
2026-02-23 17:50 UTC
Published
2026-06-09 00:20 UTC
Last updated
2026-06-09 13:03 UTC
Primary CWE
CWE-121
CWE-121: Stack-based Buffer Overflow
Vendor / Product
SAP_SE / SAP NetWeaver AS ABAP and ABAP Platform
Sources
cve.org  ·  NVD

Severity & Metrics

9.8 CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Exploitation
none
Automatable
yes
Tech. Impact
total
Affected products (1)
VendorProductPlatformVersions
SAP_SE SAP NetWeaver AS ABAP and ABAP Platform KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 722EXT …
Weakness (CWE)
CWESourceDescription
CWE-121 cna CWE-121: Stack-based Buffer Overflow
CVSS scores (1)
ScoreSeverityVersionSourceVector
9.8 CRITICAL 3.1 cna CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Back to overview