Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
5022 articles · 188920 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-34265
sap · sap netweaver and abap platform

Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform

Description

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

Affected Products

VendorProductVersions
sapsap netweaver and abap platformKRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT2, 7.22EXT3, 7.53, 7.54, 7.77, 7.89, 7.93, 8.04, 9.16 9.18, 9.19, KERNEL 7.22, 9.16, 9.18

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
sapsap softwarecert_advisory90%

References

  • https://me.sap.com/notes/3714806
  • https://url.sap/sapsecuritypatchday

Related News (5 articles)

Tier D
SecurityWeek1d ago
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
→ No new info (linked only)
Tier D
Heise Security1d ago
Patchday: SAP Commerce Cloud komplett kompromittierbar
→ No new info (linked only)
Tier B
BSI Advisories1d ago
[NEU] [hoch] SAP Patch Day August 2026: Mehrere Schwachstellen
→ No new info (linked only)
Tier C
VulDB1d ago
CVE-2026-34265 | SAP NetWeaver and ABAP Platform up to KRNL64UC 7.22 DIAG Protocol memory corruption
→ No new info (linked only)
Tier B
CERT-FR1d ago
Multiples vulnérabilités dans les produits SAP (11 août 2026)
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-787
PublishedAug 11, 2026
Trending Score61
Source articles5
Independent5
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-58231
Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)
Trending: 69
CRITICALCVE-2026-44758
Code Injection vulnerability in Manufacturing Integration and Intelligence
Trending: 52
HIGHCVE-2026-44764
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 46
HIGHCVE-2026-44765
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 46
MEDIUMCVE-2026-40130
Memory Corruption vulnerability in SAPSPrint Service
Trending: 43

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026