CVE-2026-27685Patch

MEDIUMCVSS 9.1 · CRITICAL

Exploitation observed; activity peaked at 8 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a high impact on the confidentiality, integrity, and availability of the host system.

5.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-502

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 12 mentions across 3 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 9 signals
  • Disclosure: 3 classified signals
  • General: 3 classified signals
  • Peaked 2d ago at 8 mentions (2026-03-10); latest day: 1
  • 12 total mentions across 3 days

Deep dive

Activity timeline12 mentions / 3d
02468Mentions · 2026-03-10: 8Mentions · 2026-03-11: 3Mentions · 2026-04-18: 1PoC Mentioned / Linked · 2026-03-11: 1Active Exploitation · 2026-03-11: 1Patch / Workaround · 2026-03-10: 4Patch / Workaround · 2026-03-11: 1Technical Details · 2026-03-10: 7Technical Details · 2026-03-11: 203-1003-1104-18
Signal classification4 categories
Patch
541.7%
Disclosure
325.0%
General
325.0%
Active Exploitation
18.3%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-03-108
Disclosure3General1Patch4
2026-03-113
Active Exploitation1General1Patch1
2026-04-181
General1
Full discourse12 posts
  • にゃん☆たく/takumi.a@taku888infinity
    Patch

    2026年3月ぱっちちゅーずーでー ▼Microsoft 2026 年 3 月のセキュリティ更新プログラム (月例) https://www.microsoft.com/en-us/msrc/blog/2026/03/202603-security-update CVE-2026-26127 .NET のサービス拒否の脆弱性 CVE-2026-21262 SQL サーバーの特権の昇格の脆弱性 ▼SAP SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html CVE-2019-17571 SAP Quotation Management Insurance アプリケーション (FS-QUO) におけるコードインジェクションの脆弱性 CVE-2026-27685 SAP NetWeaver Enterprise Portal 管理における安全でないデシリアライゼーション ▼Ivanti(critical系はなし) March 2026 Security Update https://www.ivanti.com/blog/march-2026-security-update CVE-2026-3483 バージョン 2026.1.1 より前の Ivanti DSM で公開されている危険な方法により、ローカルで認証された攻撃者が権限を昇格できる可能性 ▼Fortinet(critical系はなし) https://fortiguard.fortinet.com/psirt CVE-2026-22627 LLDP OUIフィールドのバッファオーバーフロー CVE-2025-54820 fgtupdates サービスによるバッファオーバーフロー ▼Adobe https://helpx.adobe.com/security.html

    Post summary

    The post lists March 2026 vendor security updates, providing CVE details and links to advisory pages that confirm patches have been released, while no PoC, exploit or active exploitation is mentioned.

    100201.1K
    11.4K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    SAP's latest security update addresses 15 flaws, including critical RCE (CVE-2019-17571) and deserialization (CVE-2026-27685) vulnerabilities. Patch now. #SAPSecurity #CVE #CyberSecurity #InfoSec #PatchAlert #Vulnerability #RCE #EnterpriseSecurity #AppSec https://securityonline.info/critical-alert-saps-latest-security-update-fixes-9-8-cvss-rce-and-deserialization-flaws/

    Post summary

    The announcement focuses on SAP’s new patch update that fixes 15 flaws, including critical RCE and deserialization vulnerabilities, without providing exploit or PoC details.

    00020325
    10.6K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-27689 ❗ CVE-2026-27685 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-sap-6/ https://t.co/WIUo6G0ByP

    Post summary

    The post lists two SAP CVEs and provides links to external resources, but offers no in-text technical or exploit information.

    00010162
    6.6K followersView on X
  • Emre Doğan@emredogancloud
    Patch

    SAP just patched CVE-2026-27685 — CVSS 9.8, insecure deserialization RCE. The attack technique? The exact same Java gadget chains ysoserial was weaponizing in 2015. ObjectInputFilter has existed since Java 9. Nobody turned it on. #cybersecurity #infosec

    Post summary

    SAP has issued a patch for CVE-2026-27685, a high‑severity insecure deserialization RCE that leverages old Java gadget chains similar to ysoserial; no active exploitation or false‑positive claims are noted.

    1000032
    12 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27685 SAP NetWeaver Enterprise Portal Deserialization Vulnerability Ena... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27685 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post announces the existence of CVE‑2026‑27685, a deserialization flaw in SAP NetWeaver Enterprise Portal, and provides links for more details.

    0001039
    4.0K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    新規のCriticalが2件 [CVE-2019-17571] Code Injection vulnerability in SAP Quotation Management Insurance application (FS-QUO) [CVE-2026-27685] Insecure Deserialization in SAP NetWeaver Enterprise Portal Administration SAP Security Patch Day - March 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/march-2026.html

    Post summary

    SAP announced two new Critical vulnerabilities, CVE‑2019‑17571 and CVE‑2026‑27685, and linked to the March 2026 Security Patch Day where official patches are available.

    00010450
    6.7K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-27685: SAP NetWeaver Privilege Escalation - What It Means for Your Business and How to Respond https://hubs.li/Q04cCzwp0

    Post summary

    The post announces the SAP NetWeaver privilege escalation CVE and offers guidance, but it does not include technical details, exploits, patches, or active exploitation information.

    0000038
    29 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    Attackers chained SAP vulnerabilities to achieve full compromise: exploiting code injection in Quotation Management (CVE-2019-17571) for initial access, then leveraging insecure deserialization in NetWeaver Portal (CVE-2026-27685) for privilege escalation and lateral movement. Runtime segmentation could help limit blast radius from such privilege escalation chains. #Vulnerability 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/sap-2026-critical-vulnerabilities-patched

    Post summary

    The post reports that attackers are actively exploiting a chain of SAP vulnerabilities (CVE‑2019‑17571 and CVE‑2026‑27685) to move from initial access to privilege escalation, indicating real‑world usage.

    0000059
    1.9K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SAP released 15 security notes in March 2026 patch day, fixing critical FS-QUO Log4j deserialization (CVE-2019-17571), another critical flaw (CVE-2026-27685), and high-severity SCM DoS (CVE-2026-27689). #SAPSecurity #Log4jFix #Germany https://ift.tt/AvULCN1

    Post summary

    SAP issued a patch day with 15 security notes that remediate three critical vulnerabilities, including a Log4j deserialization flaw, another critical vulnerability, and a high‑severity SCM denial‑of‑service issue.

    00000117
    3.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-27685: CRITICAL] Beware of vulnerabilities in SAP NetWeaver Enterprise Portal Administration! Uploading malicious content by privileged users could severely impact system security. #cybersecurity#cve,CVE-2026-27685,#cybersecurity https://cvefind.com/CVE-2026-27685

    Post summary

    The tweet warns of a critical SAP NetWeaver vulnerability, providing basic technical details but no proof‑of‑concept, exploit code, active exploitation report, or patch information.

    0000033
    601 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27685 SAP NetWeaver Enterprise Portal Administration is vulnerable if a privileged user uploads untrusted or malicious content that, upon deserialization, could result in a… https://www.cve.org/CVERecord?id=CVE-2026-27685

    Post summary

    The post references CVE-2026-27685, noting a deserialization vulnerability when privileged users upload content, but it provides no details on exploitation, mitigations, or proof of concept.

    00000167
    56.7K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-27685: Insecure Deserialization in SAP ... Admin-level deserialization RCE in SAP NetWeaver EP-RUNTIME 7.50 - privileged user requirement won't stop lateral movem... https://zerodaysignal.com/vulnerability/CVE-2026-27685 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces CVE-2026-27685, an insecure deserialization RCE vulnerability in SAP NetWeaver EP-RUNTIME 7.50 that requires admin privileges, but it does not provide PoC, exploit code, active exploitation evidence, or patch information.

    0000063
    140 followersView on X

Explore more