Part of Lyceum Intelligence — deep-research In Focus reports → · Lyceum Corpus — ask the documents →

Full-text search across 381 articles. Typo-tolerant.

CVE-2026-27671 -- CVSS 9.8 Vulnerability Briefing

CVE-2026-27671 | CVSS 9.8 (Critical) | Exploit: No known exploit

What Is It

CVE-2026-27671 is a critical improper input validation vulnerability in the SAP Kernel component used by SAP NetWeaver Application Server ABAP and the ABAP Platform, exposing the RFC (Remote Function Call) protocol handler to unauthenticated remote attack.

Technical Detail

The flaw stems from insufficient validation of RFC protocol messages within the SAP Kernel, allowing an unauthenticated remote attacker to send a specially crafted RFC request that the server processes without proper protocol conformance checks. Successful exploitation could result in remote code execution or significant disruption to the affected ABAP application server, depending on the specific memory or logic condition triggered. Given the unauthenticated attack vector and the CVSS score of 9.8, the vulnerability is assessed as exploitable over the network with no user interaction or prior credentials required.

Exploitation Status

No known exploit code has been publicly observed or confirmed as of June 16, 2026. This vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. Exploit maturity is assessed as none at this time, though the unauthenticated network attack vector and critical severity rating make this a high-priority target for threat actors conducting reconnaissance against SAP environments.

Who Is Targeting This

No specific threat actor attribution at this time. Neither confirmed nor reported threat actor activity has been associated with this CVE as of the date of this briefing.

What To Do

Apply the relevant SAP Security Note addressing this vulnerability as part of SAP's patch release cycle immediately. Organizations running SAP NetWeaver ABAP or the ABAP Platform should treat this as a priority patch given the unauthenticated remote exploitation potential and the critical CVSS rating. As an interim measure, restrict network access to RFC ports (typically TCP 33xx and 48xx) to trusted hosts and internal networks only using firewall or network segmentation controls. Audit RFC gateway configurations and disable unnecessary RFC services where feasible. Monitor SAP system logs and network traffic for anomalous or malformed RFC connection attempts as a detection signal. Consult the SAP Support Portal for the specific Security Note number and affected kernel patch levels applicable to your environment.

All analysis →

Deep-research intelligence reports from Lyceum Intelligence — structured assessments with sourced claims and calibrated conclusions.

Browse Intelligence Reports →