CVE-2026-66767

CVE & Vulnerabilities · September 10, 2026

CVE & Vulnerabilities·nvd.nist.gov

CVE-2026-66767 is a newly disclosed flaw in SAP NetWeaver's Message Server that fails to verify whether a registering component is genuine. Anyone with plain network access to the service, without needing any credentials, can register a rogue component and abuse that trust to take actions inside the SAP environment. SAP rates the impact as severe, warning that successful abuse could compromise data confidentiality and integrity while also affecting the system's availability.

// source: nvd.nist.gov ↗

Back to Blog