VDB

CVE-2026-0487

CVE-2026-0487 PUBLISHED CVSS 8.4 HIGH

Reported by sap · Published July 14, 2026

SAProuter on Microsoft Windows allows an unauthenticated attacker to load library (DLL) files from an untrusted location, allowing them to execute malicious code on the system. This could enable the attacker to hijack the DLL loading process and achieve arbitrary code execution. This has high impact on confidentiality, integrity and availability of the system.

Risk Scores

CVSS 3.1
8.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products

VendorProductVersions
SAP_SESAProuter on Microsoft WindowsKRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22
SAP_SESAProuter on Microsoft WindowsKRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22

Timeline

  • Jul 14, 2026 EPSS Score
  • Jul 14, 2026 Coalition ESS Score
  • Jul 14, 2026 CVE Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›