critical2026-08-11SAP NetWeaverCVE-2026-34265

Unauthenticated Memory Corruption via DIAG Protocol in SAP NetWeaver AS ABAP

SAP NetWeaver AS ABAP and ABAP Platform (DIAG Protocol)

Our Take

Unauthenticated memory corruption in the DIAG protocol hits a port that every ABAP system has open on the internal network. Most SAP landscapes assume DIAG is internal-only — which is fine — but lateral movement from any compromised internal host becomes trivial exploitation. Kernel patch, restart required; coordinate with your BASIS team now.

Vulnerability Detail

Improper boundary validation in DIAG protocol parsing within SAP NetWeaver Application Server ABAP allows an unauthenticated remote attacker to send a specially crafted network packet that triggers memory corruption. Successful exploitation can lead to disclosure of sensitive information or complete system crash — and under favourable conditions, arbitrary code execution. DIAG is the native SAP GUI network protocol used by all SAPGUI connections.

Workaround

Block external access to DIAG protocol ports (32xx/33xx) at the network perimeter. DIAG should never be accessible from the internet — if it is, close it immediately regardless of this patch.

Patch Action

Apply SAP Note 3714806 (kernel-level patch). A system restart is required. Verify affected kernel versions in the official Note.

Affected Versions

KERNEL 7.22
7.53

Patch Info

Priority

🔴 Patch immediately

CVSS Score

9.8

SAP Note

3714806

CVE

CVE-2026-34265

Published

2026-08-11

← All patches