high2026-09-08SAP NetWeaver AS for ABAP and ABAP PlatformCVE-2026-66767

Memory Corruption via Session Packet Replay in AS ABAP

SAP NetWeaver AS for ABAP

Our Take

This shares the Kernel patch with the CVSS 10.0 EPP note (3747649). Two kernel-level memory corruption bugs in the same release indicates a meaningful security review cycle — or a busy month for SAP's bug reporters. If you're already patching for the critical, you get this for free.

Vulnerability Detail

Session hijacking via specially crafted packet reprocessing under timing conditions. A second kernel-level memory corruption vulnerability in September's release cycle.

Patch Action

Covered by the same Kernel patch as SAP Note 3747649. If you patched the CVSS 10.0 EPP note, this is addressed. Verify by checking the Kernel patch level in your systems.

Affected Versions

KERNEL 7.22–9.20

Patch Info

Priority

🔴 Patch immediately

CVSS Score

7.7

SAP Note

3757002

CVE

CVE-2026-66767

Published

2026-09-08

← All patches