Executive brief
SAP NetWeaver Application Server ABAP is a core middleware platform used by many enterprises to run business applications. An unauthenticated remote attacker can exploit logical errors in how the system processes DIAG protocol messages, causing memory corruption. This could allow attackers to crash the system, disrupt business operations, or potentially steal sensitive business data without needing valid credentials.
Technical details
The vulnerability exists in SAP NetWeaver Application Server ABAP's DIAG protocol parser, which handles communication between SAP GUI clients and the application server. An unauthenticated attacker on the network can send specially crafted DIAG protocol packets to exploit logical errors in the parser, triggering memory corruption. No authentication is required to trigger this issue, as the DIAG protocol is exposed at the network level. An attacker can achieve remote code execution, denial of service, or information disclosure by leveraging this memory corruption. SAP has classified this as critical severity (CVSS 9.8) and released patches via their August 2026 Security Patch Day.
Affected products
- SAP NetWeaver Application Server ABAP
Timeline
- 2026-08-11: disclosed: Published on SAP Security Patch Day
- 2026-08-11: other: CVE-2026-34265 assigned