CVE-2026-34265: pre-auth remote memory corruption in SAP SAP NetWeaver and ABAP Platform

An unauthenticated remote attacker can trigger memory corruption in SAP NetWeaver and ABAP Platform by sending crafted DIAG protocol input, potentially exposing sensitive data or causing crashes. CVE-2026-34265 affects multiple 7.x builds including KRNL64NUC 7.22, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3 and other 7.x releases listed by the vendor. Exploitation requires network access to the service that parses DIAG requests and does not require valid credentials.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.00642
CWE
CWE-787
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: this is a high-impact, pre-auth network flaw with no vendor fixes reported; prioritize isolating and reducing exposure of affected NetWeaver/ABAP instances until a patch is available.

What is CVE-2026-34265?

An unauthenticated remote attacker can trigger memory corruption in SAP NetWeaver and ABAP Platform by sending crafted DIAG protocol input, potentially exposing sensitive data or causing crashes. CVE-2026-34265 affects multiple 7.x builds including KRNL64NUC 7.22, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3 and other 7.x releases listed by the vendor. Exploitation requires network access to the service that parses DIAG requests and does not require valid credentials. The weakness is classified as CWE-787 (Out-of-bounds Write).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of SAP SAP NetWeaver and ABAP Platform are affected?

BRANCHAFFECTEDFIXED
SAP NetWeaver and ABAP PlatformKRNL64NUC 7.22
7.x7.22EXT
SAP NetWeaver and ABAP PlatformKRNL64UC 7.22
7.x7.22EXT2
7.x7.22EXT3
7.x7.53
7.x7.54
7.x7.77
7.x7.89
7.x7.93

Is CVE-2026-34265 being exploited?

There are no public reports of exploitation as of 2026-09-29.

How to fix CVE-2026-34265

  1. Isolate affected SAP NetWeaver and ABAP Platform instances from untrusted networks and avoid exposing DIAG services to the internet.
  2. Follow SAP guidance and subscribe to vendor advisories for a vendor-supplied fix; apply vendor patches as soon as they are released.
  3. Monitor SAP system logs and network traffic for anomalous DIAG protocol activity and signs of memory-corruption crashes.
  4. If possible, restrict access to management and diagnostic interfaces to trusted IPs and enforce network-level controls.

Frequently asked questions

Is CVE-2026-34265 being actively exploited?

There are no public reports of exploitation of CVE-2026-34265 as of 2026-09-29.

Which SAP NetWeaver and ABAP Platform versions are affected by CVE-2026-34265?

Affected releases include KRNL64NUC 7.22, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3 and several other 7.x builds listed by the vendor.

Is there a patch for CVE-2026-34265?

No vendor-supplied fixes are reported in the provided facts; monitor SAP advisories for a patch and deploy it when available.

Does CVE-2026-34265 require authentication?

No, the vulnerability can be triggered without authentication via crafted DIAG protocol input sent over the network.

References