
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27671 is a critical stack-based buffer overflow vulnerability in the SAP Kernel used by the Application Server ABAP of SAP NetWeaver and ABAP Platform. Due to improper RFC (Remote Function Call) protocol validation, an unauthenticated remote attacker can send a crafted RFC request that exploits logical errors in memory management, leading to memory corruption. Affected kernel versions include KERNEL 7.22, 7.22EXT, KRNL64NUC 7.22, KRNL64UC 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, and 91.9. The vulnerability was published on June 9, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (GitHub Advisory, Feedly).
The root cause is classified as CWE-121 (Stack-based Buffer Overflow), arising from insufficient validation of RFC protocol messages within the SAP Kernel (GitHub Advisory). An attacker exploits logical errors in memory management by sending a specially crafted RFC request over the network, causing a stack buffer to be overwritten with attacker-controlled data. No authentication, user interaction, or special privileges are required — the attack vector is entirely network-accessible with low complexity. The vulnerability resides in the SAP Kernel component shared across multiple SAP NetWeaver and ABAP Platform kernel versions, making the attack surface broad (Feedly).
Successful exploitation can result in high impact to confidentiality, integrity, and availability of the affected SAP application server. An unauthenticated attacker could achieve arbitrary code execution, unauthorized access to sensitive business data processed by SAP systems, or cause a complete application crash (denial of service). Given that SAP NetWeaver and ABAP Platform are commonly used as core ERP infrastructure, exploitation could enable lateral movement into connected enterprise systems and exposure of highly sensitive financial, HR, or operational data (GitHub Advisory, Feedly).
SAP has released patches for this vulnerability as part of the June 2026 SAP Security Patch Day; administrators should apply the relevant SAP Security Note 3717897 immediately via the SAP Support Portal (SAP Security Note, SAP Patch Day). As interim workarounds, implement network segmentation to restrict RFC protocol access (TCP ports 3300+) to only trusted internal systems and SAP-to-SAP communication paths. Consider disabling RFC gateway services if they are not required for business operations. Monitor SAP gateway logs for suspicious RFC connection attempts from unauthorized sources (Feedly, Onapsis).
The vulnerability received significant coverage as part of SAP's June 2026 Security Patch Day, which addressed four critical vulnerabilities. Security outlets including BleepingComputer, SecurityWeek, The Hacker News, and Heise reported on the patch day, highlighting CVE-2026-27671 alongside other critical SAP flaws (BleepingComputer, SecurityWeek, The Hacker News). SAP security specialists Onapsis, SecurityBridge, RedRays, and Layer Seven Security published detailed patch day analyses emphasizing the critical nature of the RFC memory corruption flaw (Onapsis, SecurityBridge). Government cybersecurity agencies including Belgium's CCB and Singapore's CSA issued advisories urging organizations to apply patches promptly (Feedly).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."