CVE-2026-27671

Published Jun 9, 2026

Last updated a month ago

Overview

Description
Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform, an unauthenticated attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. This could lead to a high impact on the confidentiality, integrity, and availability of the application.
Source
cna@sap.com
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

cna@sap.com
CWE-121

Social media

Hype score
Not currently trending
  1. SAP June Patch Day: 15 security notes, 4 critical. CVE-2026-44748 (CVSS 9.9) — XML Signature Wrapping bypass in NetWeaver SAML. CVE-2026-27671 (CVSS 9.8) — unauthenticated memory corruption in ABAP RFC gateway. https://t.co/URyHYrF8Aa #CyberSecurity #Vulne https://t.co/vngyJi

    @securitydailyr

    11 Jun 2026

    40 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 NEW: SAP June Patch Day — 4 critical flaws, top CVSS 9.9. The worst: CVE-2026-44748 lets a low-privileged user forge SAML assertions and bypass authentication entirely on NetWeaver ABAP. CVE-2026-27671 (CVSS 9.8) is unauthenticated memory corruption via crafted RFC request

    @CyberAlertsHQ

    9 Jun 2026

    75 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  3. SAP released 15 security notes addressing four critical flaws including CVE-2026-44748 and CVE-2026-27671 in NetWeaver and other core products, Belgium's Centre for Cybersecurity said. https://t.co/V0QlgiVYvz

    @threatcluster

    9 Jun 2026

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. Warning: #SAP has released security updates for 15 vulnerabilities in several of their products, including 4 critical vulnerabilities: #CVE-2026-44748; #CVE-2026-27671; #CVE-2026-40128 and #CVE-2026-22732. Read our advisory here: https://t.co/cVlLvwsEYZ #Patch #Patch #Patch

    @CCBalert

    9 Jun 2026

    107 Impressions

    2 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 🚨 CVE-2026-27671 — CVSS 9.8/10 ██████████ Due to improper RFC protocol validation in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/ZZ2W8zEIHi

    @OrizonCyber

    9 Jun 2026

    84 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

References

Sources include official advisories and independent security research.