Junglewise Threat Intelligence

CVE-2026-27671: SAP NetWeaver and ABAP Platform memory corruption in SAP Kernel

CVE-2026-27671 · Severity: critical · CVSS 9.8 · Published 2026-06-09

Technologies: SAP NetWeaver Application Server ABAP. Vendors: SAP.

Executive brief

A critical vulnerability exists in the SAP Kernel, the core engine powering SAP NetWeaver and ABAP platforms. An attacker can exploit this flaw over the network without any login credentials to cause memory corruption on the server. This could allow an unauthorized party to gain full control over the application, potentially leading to the theft of sensitive business data, system downtime, or unauthorized modification of records.

Technical details

A stack-based buffer overflow (CWE-121) exists in the SAP Kernel used by SAP NetWeaver Application Server ABAP and the ABAP Platform. The vulnerability is rooted in improper validation of Remote Function Call (RFC) protocol requests. An unauthenticated remote attacker can send a specially crafted RFC request to trigger logical errors in memory management, leading to memory corruption. Successful exploitation provides the attacker with high-impact access to confidentiality, integrity, and availability, effectively allowing for arbitrary code execution or complete system takeover. SAP has released security note 3717897 to address this issue.

Affected products

  • SAP NetWeaver Application Server ABAP All versions using affected SAP Kernel
  • SAP ABAP Platform All versions using affected SAP Kernel

Timeline

  • 2026-06-09: advisory: Initial disclosure by SAP during June 2026 Patch Day

References

Related threats