DIRAS TAKE
Urgent: this is a high-impact, pre-auth network flaw with no vendor fixes reported; prioritize isolating and reducing exposure of affected NetWeaver/ABAP instances until a patch is available.
What is CVE-2026-34265?
An unauthenticated remote attacker can trigger memory corruption in SAP NetWeaver and ABAP Platform by sending crafted DIAG protocol input, potentially exposing sensitive data or causing crashes. CVE-2026-34265 affects multiple 7.x builds including KRNL64NUC 7.22, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3 and other 7.x releases listed by the vendor. Exploitation requires network access to the service that parses DIAG requests and does not require valid credentials. The weakness is classified as CWE-787 (Out-of-bounds Write).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of SAP SAP NetWeaver and ABAP Platform are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| SAP NetWeaver and ABAP Platform | KRNL64NUC 7.22 | |
| 7.x | 7.22EXT | |
| SAP NetWeaver and ABAP Platform | KRNL64UC 7.22 | |
| 7.x | 7.22EXT2 | |
| 7.x | 7.22EXT3 | |
| 7.x | 7.53 | |
| 7.x | 7.54 | |
| 7.x | 7.77 | |
| 7.x | 7.89 | |
| 7.x | 7.93 |
Is CVE-2026-34265 being exploited?
There are no public reports of exploitation as of 2026-09-29.
How to fix CVE-2026-34265
- Isolate affected SAP NetWeaver and ABAP Platform instances from untrusted networks and avoid exposing DIAG services to the internet.
- Follow SAP guidance and subscribe to vendor advisories for a vendor-supplied fix; apply vendor patches as soon as they are released.
- Monitor SAP system logs and network traffic for anomalous DIAG protocol activity and signs of memory-corruption crashes.
- If possible, restrict access to management and diagnostic interfaces to trusted IPs and enforce network-level controls.
Frequently asked questions
Is CVE-2026-34265 being actively exploited?
There are no public reports of exploitation of CVE-2026-34265 as of 2026-09-29.
Which SAP NetWeaver and ABAP Platform versions are affected by CVE-2026-34265?
Affected releases include KRNL64NUC 7.22, KRNL64UC 7.22, 7.22EXT, 7.22EXT2, 7.22EXT3 and several other 7.x builds listed by the vendor.
Is there a patch for CVE-2026-34265?
No vendor-supplied fixes are reported in the provided facts; monitor SAP advisories for a patch and deploy it when available.
Does CVE-2026-34265 require authentication?
No, the vulnerability can be triggered without authentication via crafted DIAG protocol input sent over the network.
References
- nvd.nist.gov/vuln/detail/CVE-2026-34265
- cve.org/CVERecord?id=CVE-2026-34265
- me.sap.com/notes/3714806
- url.sap/sapsecuritypatchday
- All SAP CVEs on CVE Radar
- CVEs published in September 2026