CVE-2026-34265 PUBLISHED

Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform

Assigner: sap
Reserved: 26.03.2026 Published: 11.08.2026 Updated: 11.08.2026

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor SAP_SE
Product SAP NetWeaver and ABAP Platform
Versions Default: unaffected
  • Version KRNL64NUC 7.22 is affected
  • Version 7.22EXT is affected
  • Version KRNL64UC 7.22 is affected
  • Version 7.22EXT2 is affected
  • Version 7.22EXT3 is affected
  • Version 7.53 is affected
  • Version 7.54 is affected
  • Version 7.77 is affected
  • Version 7.89 is affected
  • Version 7.93 is affected
  • Version 8.04 is affected
  • Version 9.16 9.18 is affected
  • Version 9.19 is affected
  • Version KERNEL 7.22 is affected
  • Version 9.16 is affected
  • Version 9.18 is affected

References

Problem Types