PT-2026-47529 · Sap · Sap Kernel+2
CVE-2026-27671
·
Published
2026-06-09
·
Updated
2026-07-14
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
SAP NetWeaver Application Server ABAP (affected versions not specified)
SAP ABAP Platform (affected versions not specified)
Description
Improper RFC (Remote Procedure Call) protocol validation in the SAP Kernel allows an unauthenticated attacker to send a crafted RFC request. This exploits logical errors in memory management, resulting in memory corruption. Such an exploit can lead to unauthenticated access, privilege escalation through missing authorization checks to gain administrative control, and high impact on the confidentiality, integrity, and availability of the application.
Recommendations
Apply SAP Security Note 3717897.
Review SAP Security Patch Day updates.
Isolate affected systems immediately.
Fix
RCE
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Abap Platform
Sap Kernel
Sap Netweaver