- Description
- Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
- Source
- cna@sap.com
- NVD status
- Awaiting Analysis
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
- cna@sap.com
- CWE-121
- Hype score
- Not currently trending
SAP June Patch Day: 15 security notes, 4 critical. CVE-2026-44748 (CVSS 9.9) — XML Signature Wrapping bypass in NetWeaver SAML. CVE-2026-27671 (CVSS 9.8) — unauthenticated memory corruption in ABAP RFC gateway. https://t.co/URyHYrF8Aa #CyberSecurity #Vulne https://t.co/vngyJi
@securitydailyr
11 Jun 2026
40 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 NEW: SAP June Patch Day — 4 critical flaws, top CVSS 9.9. The worst: CVE-2026-44748 lets a low-privileged user forge SAML assertions and bypass authentication entirely on NetWeaver ABAP. CVE-2026-27671 (CVSS 9.8) is unauthenticated memory corruption via crafted RFC request
@CyberAlertsHQ
9 Jun 2026
75 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
SAP released 15 security notes addressing four critical flaws including CVE-2026-44748 and CVE-2026-27671 in NetWeaver and other core products, Belgium's Centre for Cybersecurity said. https://t.co/V0QlgiVYvz
@threatcluster
9 Jun 2026
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Warning: #SAP has released security updates for 15 vulnerabilities in several of their products, including 4 critical vulnerabilities: #CVE-2026-44748; #CVE-2026-27671; #CVE-2026-40128 and #CVE-2026-22732. Read our advisory here: https://t.co/cVlLvwsEYZ #Patch #Patch #Patch
@CCBalert
9 Jun 2026
107 Impressions
2 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🚨 CVE-2026-27671 — CVSS 9.8/10 ██████████ Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/ZZ2W8zEIHi
@OrizonCyber
9 Jun 2026
84 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes