ZeroHour

CVE-2026-0509

CVSS 3.1
9.6 critical
EPSS
<1%p28
Published
()
Modified
Description

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

Vendors
sap
Products
netweaver as abap kernel, netweaver as abap krnl64nuc, netweaver as abap krnl64uc
Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H

In the news