CVE-2026-27671: SAP SE SAP NetWeaver As Abap And Abap Platform

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.

Affected products

  • SAP SE SAP NetWeaver As Abap And Abap Platform: version 7.22EXT only; version 722EXT only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.89 only; …

Published 2026-06-09. Last modified 2026-07-23.