CVE-2026-27689General

LOWCVSS 7.7 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedly invoke a remote-enabled function module with an excessively large loop-control parameter. This triggers prolonged loop execution that consumes excessive system resources, potentially rendering the system unavailable. Successful exploitation results in a denial-of-service condition that impacts availability, while confidentiality and integrity remain unaffected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-606

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 3 mentions (2026-03-10); latest day: 2
  • 5 total mentions across 2 days

Deep dive

Activity timeline5 mentions / 2d
01223Mentions · 2026-03-10: 3Mentions · 2026-03-11: 2Patch / Workaround · 2026-03-10: 1Technical Details · 2026-03-10: 303-1003-11
Signal classification3 categories
General
240.0%
Disclosure
240.0%
Patch
120.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-03-103
General2Patch1
2026-03-112
Disclosure2
Full discourse5 posts
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-27689 ❗ CVE-2026-27685 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-sap-6/ https://t.co/WIUo6G0ByP

    Post summary

    A notice highlighting SAP product vulnerabilities CVE-2026-27689 and CVE-2026-27685, directing readers to additional information via provided links.

    00010162
    6.6K followersView on X
  • RedPacket Security@RedPacketSec
    Disclosure

    CVE Alert: CVE-2026-27689 - SAP_SE - SAP Supply Chain Management - https://www.redpacketsecurity.com/cve-alert-cve-2026-27689-sap-se-sap-supply-chain-management/ #OSINT #ThreatIntel #CyberSecurity #cve-2026-27689 #sap-se #sap-supply-chain-management

    Post summary

    The tweet announces the CVE (CVE-2026-27689) with a link to an alert page but provides no further technical details, fixes, or exploitation information.

    0000062
    3.5K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    SAP released 15 security notes in March 2026 patch day, fixing critical FS-QUO Log4j deserialization (CVE-2019-17571), another critical flaw (CVE-2026-27685), and high-severity SCM DoS (CVE-2026-27689). #SAPSecurity #Log4jFix #Germany https://ift.tt/AvULCN1

    Post summary

    The tweet announces SAP’s March 2026 patch day releases three critical/fix notes for specific CVEs, highlighting the availability of vendor patches rather than exploits or active attacks.

    00000117
    3.7K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-27689 Due to an uncontrolled resource consumption (Denial of Service) vulnerability, an authenticated attacker with regular user privileges and network access can repeatedl… https://www.cve.org/CVERecord?id=CVE-2026-27689

    Post summary

    The tweet provides a brief description of CVE‑2026‑27689 as an uncontrolled resource consumption denial‑of‑service vulnerability, but offers no PoCs, exploits, active attack details, patch information, or false‑positive claims.

    00000174
    56.7K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-27689 - Denial of service (DOS) in SAP Supply Chain Management Intel Report: https://ift.tt/8Vn3wW7

    Post summary

    The alert briefly notes that CVE‑2026‑27689 causes a denial‑of‑service in SAP Supply Chain Management and points to an external Intel report for more information.

    0000044
    345 followersView on X

Explore more