CVE-2026-27671
A flaw in how the SAP Kernel handles certain network protocols can cause errors in how the system manages its memory. This allows an attacker to send a specially crafted request to trigger memory corruption.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Users of SAP NetWeaver and ABAP Platform using the SAP Kernel in the Application Server ABAP.
Real-world impact
An attacker could potentially gain unauthorized access to sensitive data, modify information, or cause the entire application to crash and become unavailable.
Why this severity
This vulnerability is rated critical because it can be exploited remotely over a network without any user interaction or authentication, and it can compromise the system's confidentiality, integrity, and availability.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jun 9, 2026 · Jun 9, 2026PublishedDisclosed and added to the National Vulnerability Database.
- Jul 23, 2026 · 12d agoAdvisory updatedThe NVD record was last revised.