VDB

CVE-2026-24320

CVE-2026-24320 PUBLISHED CVSS 3.0999999046325684 LOW

Due to improper memory management in SAP NetWeaver and ABAP Platform (Application Server ABAP), an authenticated attacker could exploit logical errors in memory management by supplying specially crafted input containing unique characters, which are improperly converted. This may result in memory corruption and the potential leakage of memory content. Successful exploitation of this vulnerability would have a low impact on the confidentiality of the application, with no effect on its integrity or availability.

EPSS 0.01% · 2.8th percentile

Risk Scores

CVSS 3.1
3.0999999046325684
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N
EPSS Score
0.01%
2.8th percentile

Affected Products

VendorProductVersions
sapnetweaver_as_abap_krnl64nuc7.22, *
sapnetweaver_as_abap_kernel7.77, 9.16, 9.18
SAP_SESAP NetWeaver and ABAP Platform (Application Server ABAP)9.16, 9.18, 7.89
sapnetweaver_as_abap_krnl64uc7.22

Timeline

  • Feb 10, 2026 CVE Published
  • Feb 10, 2026 EPSS Score
  • Feb 12, 2026 EPSS Score
  • Feb 14, 2026 EPSS Score
  • Feb 15, 2026 CVE Updated
  • Feb 16, 2026 EPSS Score
  • Feb 18, 2026 EPSS Score
  • Feb 20, 2026 EPSS Score
  • Feb 22, 2026 EPSS Score
  • Feb 24, 2026 EPSS Score
  • Feb 26, 2026 EPSS Score
  • Feb 28, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›