DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:05:39ZSOURCES: 14CRITICAL: 26
⚠ ACTIVE ALERTS
@GossiTheDog CRITICAL — Confirmed: FortiBleed (CVE campaign + brute force) has produced ~86,644 verified… /// @MandiantThreats CRITICAL — FortiBleed is an active, industrialized credential-harvesting campaign, not a single CVE… /// @TalosSecurity CRITICAL — DragonForce ransomware (tracked as Hackledorb) deployed novel Go-based Backdoor.Turn… /// @vxunderground CRITICAL — The Gentlemen RaaS (admin: hastalamuerte/zeta88, ex-Qilin ArmCorp affiliate) has claimed… /// @MalwareHunterTeam CRITICAL — 24 billion record infostealer credential cluster discovered June 12 by Cybernews — 8.3TB…
26Critical Threats
20Active CVEs
13IOCs Tracked
6New Advisories
TLP:WHITEVULNERABILITY BRIEF // CVE-2026-27671PUBLISHED: 2026-06-09
CRITICALCVE-2026-27671

SAP NetWeaver ABAP Kernel Unauthenticated Memory Corruption RCE

VENDOR: SAP//PRODUCT: SAP NetWeaver Application Server ABAP / ABAP Platform (SAP Kernel)
9.8
CRITICAL
CVSS 3.1
PATCH STATUS
PATCH AVAILABLE
EXPLOIT STATUS
NO KNOWN EXPLOIT

A memory corruption vulnerability (CWE-121, stack-based buffer overflow) in the SAP Kernel's RFC (Remote Function Call) protocol handler allows an unauthenticated remote attacker to send a specially crafted RFC request that exploits logical errors in memory management. Successful exploitation can result in application crashes, unauthorized data access, or arbitrary code execution. CISA's ADP assessment flagged this flaw as automatable, meaning it is exploitable at scale. No workaround exists — the only remediation is a kernel-level patch.

Attack Vector
NETWORK
Attack Complexity
LOW
Privs Required
NONE
User Interaction
NONE
Scope / Impact
UNCHANGED
C:H · I:H · A:H
AFFECTED VERSIONSSAP NetWeaver and ABAP Platform — requires kernel update; no workaround available
  • https://www.securityweek.com/sap-patches-critical-netweaver-commerce-vulnerabilities/
  • https://socradar.io/blog/sap-security-patch-day-june-2026-cve-2026-44748/
  • https://www.bleepingcomputer.com/news/security/sap-fixes-critical-flaws-in-netweaver-and-commerce-cloud/
  • https://erp.today/sap-june-2026-patch-day-critical-fixes-netweaver-abap-commerce-cloud/
SHARE BRIEF:✕ Post on Xin Share on LinkedIn