Critical severity9.8NVD Advisory· Published Jun 9, 2026· Updated Jun 9, 2026
CVE-2026-27671
CVE-2026-27671
Description
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3Patches
Vulnerability mechanics
References
2News mentions
6- ⚡ Weekly Recap: Chrome 0-Day, UniFi Exploits, macOS Stealers, VPN Flaw and MoreThe Hacker News · Jun 15, 2026
- Ivanti, Fortinet, and SAP Release Patches for Multiple Critical VulnerabilitiesThe Hacker News · Jun 10, 2026
- SAP fixes critical flaws in NetWeaver and Commerce CloudBleepingComputer · Jun 9, 2026
- SAP Patches Critical NetWeaver, Commerce VulnerabilitiesSecurityWeek · Jun 9, 2026
- SAP Security Patch Day – Critical Vulnerabilities in SAP NetWeaver PatchedCyber Security News · Jun 9, 2026
- SAP: Twelve Vulnerabilities Disclosed Together on June 9, 2026Vypr Intelligence · Jun 9, 2026