CVE-2026-34265: Out-of-Bounds Write in SAP NetWeaver ABAP
August 12, 2026
A critical out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform (CVSS 9.8) allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This can lead to disclosure of sensitive system information or system crashes.