CVE-2026-27671: Memory Corruption vulnerability in Application Server ABAP of SAP NetWeaver and ABAP Platform
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-27671?
CVE-2026-27671 has a critical severity rating of 9.8.
What type of vulnerability is identified in CVE-2026-27671?
CVE-2026-27671 is a memory corruption vulnerability in the Application Server ABAP of SAP NetWeaver and ABAP Platform.
Who can exploit the vulnerability CVE-2026-27671?
An unauthenticated attacker can exploit CVE-2026-27671 through a crafted RFC request.
What impact can result from the exploitation of CVE-2026-27671?
Exploitation of CVE-2026-27671 can lead to high impact consequences, including loss of integrity and availability.
How do I fix CVE-2026-27671?
To fix CVE-2026-27671, you should apply the latest security patches from SAP as recommended in their advisory.