CVE-2026-34265Active Exploitation

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system information or crash the system, leading to a high impact on the confidentiality, integrity, and availability of the application.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-18: 1Active Exploitation · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 108-18
Signal classification1 categories
Active Exploitation
1100.0%
Full discourse1 post
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: multiple critical code injection, out-of-bounds write in #SAP #commercecloud #netweaver #MII CVE-2026-58231, CVE-2026-44772, CVE-2026-34265 & CVE-2026-44758 CVSS: 10-9.1 The first one is actively exploited #Patch #Patch #Patch

    Post summary

    The post issues a warning about multiple severe SAP vulnerabilities, noting that the first CVE is reportedly being exploited in the wild and urging patching.

    00000294
    7.2K followersView on X

Explore more