PT-2026-47529 · Sap · Sap Kernel+2

CVE-2026-27671

·

Published

2026-06-09

·

Updated

2026-07-14

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions SAP NetWeaver Application Server ABAP (affected versions not specified) SAP ABAP Platform (affected versions not specified)
Description Improper RFC (Remote Procedure Call) protocol validation in the SAP Kernel allows an unauthenticated attacker to send a crafted RFC request. This exploits logical errors in memory management, resulting in memory corruption. Such an exploit can lead to unauthenticated access, privilege escalation through missing authorization checks to gain administrative control, and high impact on the confidentiality, integrity, and availability of the application.
Recommendations Apply SAP Security Note 3717897. Review SAP Security Patch Day updates. Isolate affected systems immediately.

Fix

RCE

Stack Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-08447
CVE-2026-27671

Affected Products

Abap Platform
Sap Kernel
Sap Netweaver