CVE-2026-0488Patch(sap / netweaver_application_server_abap)

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch sap netweaver_application_server_abap systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function module call and execute unauthorized critical functionalities, which includes the ability to execute an arbitrary SQL statement. This leads to a full database compromise with high impact on confidentiality, integrity, and availability.

4.0/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netweaver_application_server_abap
  • s\/4hana
  • webclient_ui_framework

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 18 mentions across 7 observed days
  • Momentum state: declining

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 11 signals
  • Technical details provided in 15 signals
  • Disclosure: 6 classified signals
  • General: 2 classified signals
  • Peaked 6d ago at 9 mentions (2026-02-10); latest day: 1
  • 18 total mentions across 7 days

Affected systems

Vendors
Products
netweaver_application_server_abaps\/4hanawebclient_ui_framework

17 versions affected across 3 products

Deep dive

Activity timeline18 mentions / 7d
02579Mentions · 2026-02-10: 9Mentions · 2026-02-11: 1Mentions · 2026-02-12: 4Mentions · 2026-02-13: 1Mentions · 2026-02-15: 1Mentions · 2026-02-18: 1Mentions · 2026-04-24: 1Active Exploitation · 2026-02-12: 1Patch / Workaround · 2026-02-10: 6Patch / Workaround · 2026-02-12: 3Patch / Workaround · 2026-02-18: 1Patch / Workaround · 2026-04-24: 1Technical Details · 2026-02-10: 8Technical Details · 2026-02-12: 3Technical Details · 2026-02-13: 1Technical Details · 2026-02-15: 1Technical Details · 2026-02-18: 1Technical Details · 2026-04-24: 102-1002-1102-1202-1302-1502-1804-24
Signal classification3 categories
Patch
1055.6%
Disclosure
633.3%
General
211.1%
Referenced assets39 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-109
Disclosure3Patch6
2026-02-111
General1
2026-02-124
General1Patch3
2026-02-131
Disclosure1
2026-02-151
Disclosure1
2026-02-181
Patch1
2026-04-241
Disclosure1
Full discourse18 posts
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Disclosure

    🚨 CVE-2026-0488: SAP CRM and SAP S/4HANA Scripting Editor has a code injection flaw that lets an authenticated low‑privilege user execute arbitrary SQL via a generic function module, leading to full database compromise (CVSS 9.9, Critical). Treat this as backbone ERP impact and apply the February SAP Security Notes immediately. #SAP #S4HANA #CVE20260488 #RCE #ERP #infosec Source: https://www.cve.org/CVERecord?id=CVE-2026-0488

    Post summary

    The post announces the CVE-2026-0488 code injection flaw in SAP products, details its severity, and urges applying the February 2026 security notes.

    20040104
    1.7K followersView on X
  • Wh1teCoon@Wh1teCoon
    Patch

    SAP just patched CVE-2026-0488 in CRM and S/4HANA — sql injection with a casual CVSS 9.9. Authenticated attacker runs arbitrary sql, full database compromise. But yeah your ERP is probably fine #SAP #SQLi #infosec

    Post summary

    SAP has released a patch for CVE-2026-0488, a high‑severity SQL injection that allows authenticated attackers to execute arbitrary SQL and fully compromise the database. No evidence of active exploitation or PoC is mentioned.

    20021220
    65 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SAP February Patch Day Fixes Critical Code Injection in CRM/S/4HANA and NetWeaver Auth Flaw SAP’s February 10, 2026 patch day shipped 26 new notes + 1 update, led by CVE-2026-0488 (CVSS 9.9) code injection in SAP CRM/S/4HANA Scripting Editor and CVE-2026-0509 (CVSS 9.6) missing authorization in NetWeaver AS ABAP/ABAP Platform—both enabling low-priv authenticated users to escalate into high-impact compromise. Additional fixes include XML Signature Wrapping and multiple DoS/redirect issues across SAP components, so SAP landscapes should prioritize patching and reduce exposure of user-facing endpoints. 🎯 Target: Global/Enterprise (SAP) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/sap-security-patch-day-feburary/

    Post summary

    SAP’s February 2026 patch day addressed critical code‑injection and authorization flaws in CRM/S/4HANA and NetWeaver, urging immediate patching to mitigate the high‑severity vulnerabilities.

    0000277
    191 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    新規のCriticalが2件 [CVE-2026-0488] Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor) [CVE-2026-0509] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform SAP Security Patch Day - February 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2026.html

    Post summary

    The post announces two new critical SAP vulnerabilities and directs readers to a February 2026 patch day with a vendor advisory link, indicating available remediation.

    10010716
    6.7K followersView on X
  • CVEFind.com@CveFindCom
    Disclosure

    [CVE-2026-0488: CRITICAL] Risk alert! SAP CRM and SAP S/4HANA users beware - authenticated attackers can exploit a flaw to execute unauthorized critical functions, risking full database compromise. #CyberSecurity#cve,CVE-2026-0488,#cybersecurity https://cvefind.com/CVE-2026-0488

    Post summary

    The tweet alerts SAP CRM and SAP S/4HANA users to a critical vulnerability (CVE‑2026‑0488) that permits authenticated attackers to perform unauthorized critical functions, potentially compromising the full database.

    0101097
    583 followersView on X
  • iototsecnews@iototsecnews
    Patch

    SAP の脆弱性 CVE-2026-0488/0509/23687 などが FIX:CRM や S/4HANA にコード・インジェクションの恐れ https://iototsecnews.jp/2026/02/10/sap-security-patch-day-fixes-critical-code-injection-flaw-in-sap-crm-and-s-4hana/ SAP の 2026年2月10日の Patch Day で、複数の脆弱性が修正されました。その中で、最も深刻なものは、SAP CRM や S/4HANA のスクリプト編集機能 (Scripting Editor) における、入力されたプログラム・コードに対する不十分な検証の脆弱性 CVE-2026-0488 (CVSS:9.9) です。本来は限られた操作しかできないはずの低権限ユーザーであっても、この脆弱性を悪用することでコード・インジェクションを引き起こし、システム内部で命令を実行できてしまいます。また、脆弱性 CVE-2026-0509 (CVSS:9.6) も、認可チェックの欠如により、権限を越えた操作を許してしまう危険なものです。ご利用のチームは、ご注意ください。 #CVE202512383 #CVE20260485 #CVE20260488 #CVE20260490 #CVE20260508 #CVE20260509 #CVE202623687 #CVE202623689 #CVE202624322 #PatchTuesday #SAP #Vulnerability

    Post summary

    The article reports SAP’s 2026‑02‑10 Patch Day, which addressed severe code‑injection and privilege‑escalation flaws in CRM and S/4HANA, citing CVSS scores and confirming official patches are available.

    01000145
    484 followersView on X
  • Machina Record@MachinaRecord
    Patch

    【リンク集:2月10日〜12日のセキュリティ関連ニュース/記事】 <脆弱性> ・Windows 11のメモ帳に脆弱性、Markdownリンク経由でファイルがサイレント実行される(CVE-2026-20841) https://www.bleepingcomputer.com/news/microsoft/windows-11-notepad-flaw-let-files-execute-silently-via-markdown-links/ ・マイクロソフトが2026年2月の月例パッチをリリース、ゼロデイ6件含む58件の脆弱性を修正(CVE-2026-21510、CVE-2026-21513他) https://www.bleepingcomputer.com/news/microsoft/microsoft-february-2026-patch-tuesday-fixes-6-zero-days-58-flaws/ ・SAPが重大な脆弱性を複数修正 CRMやS/4HANA、NetWeaverに存在(CVE-2026-0488、CVE-2026-0509他) https://www.securityweek.com/sap-patches-critical-crm-s-4hana-netweaver-vulnerabilities/ ・米CISA、Microsoft OfficeとMicrosoft Windowsの脆弱性をKEVカタログに追加(CVE-2026-21510、CVE-2026-21513他) https://securityaffairs.com/187855/security/u-s-cisa-adds-microsoft-office-and-microsoft-windows-flaws-to-its-known-exploited-vulnerabilities-catalog.html ・ICS月例パッチ:シーメンス、シュナイダーエレクトリック、アヴィバ、フエニックス・コンタクトが脆弱性を修正 https://www.securityweek.com/ics-patch-tuesday-vulnerabilities-addressed-by-siemens-schneider-aveva-phoenix-contact/ ・GoogleとIntelのセキュリティ監査でTDXに深刻な脆弱性が見つかる 完全な侵害を許す恐れ(CVE-2025-32007、CVE-2025-27940他) https://www.securityweek.com/google-intel-security-audit-reveals-severe-tdx-vulnerability-allowing-full-compromise/ ・Fortinet、深刻度の高い脆弱性を修正(CVE-2025-52436、CVE-2026-22153他) https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities/ <マルウェア・その他脅威> ・北朝鮮のハッカーグループ、新たなmacOSマルウェアで暗号資産窃取を目論む https://www.bleepingcomputer.com/news/security/north-korean-hackers-use-new-macos-malware-in-crypto-theft-attacks/ ・新たなLinuxボットネットのSSHStalker、C2通信に旧式のIRCを使用 https://www.bleepingcomputer.com/news/security/new-linux-botnet-sshstalker-uses-old-school-irc-for-c2-comms/ ・GoogleカレンダーのAIコネクタがマルウェアを起動する恐れ 複数の研究者が指摘 https://www.theregister.com/2026/02/11/claude_desktop_extensions_prompt_injection/ ・モバイル端末へのフルアクセスを可能にするスパイウェア「ZeroDayRAT」 https://securityaffairs.com/187820/malware/zerodayrat-spyware-grants-attackers-total-access-to-mobile-devices.html ・CastleLoaderマルウェアを使ったキャンペーンでLummaStealer感染が急増 https://www.bleepingcomputer.com/news/security/lummastealer-infections-surge-after-castleloader-malware-campaigns/ <ランサムウェア> ・Crazyランサムウェアグループ、従業員監視ツールを攻撃に悪用 https://www.bleepingcomputer.com/news/security/crazy-ransomware-gang-abuses-employee-monitoring-tool-in-attacks/ ・「Reynolds」ランサムウェア、ペイロードにBYOVD用ドライバを埋め込む https://www.darkreading.com/threat-intelligence/black-basta-bundles-byovd-ransomware-payload <データ侵害/サイバー犯罪> ・Conduentのデータ侵害でボルボ・グループに被害、約17,000人分の従業員データが流出 https://www.securityweek.com/conduent-breach-hits-volvo-group-nearly-17000-employees-data-exposed/ ・米ジョージア州の医療関連企業でデータ侵害、62万人以上に影響 https://therecord.media/georgia-healthcare-company-data-breach-impacts-620000 <AI関連> ・Amazon、新たなマーケットプレイスの立ち上げを示唆 メディアサイトがAI企業へコンテンツを販売できる場に https://techcrunch.com/2026/02/10/amazon-may-launch-a-marketplace-where-media-sites-can-sell-their-content-to-ai-companies/ ・中国最大のハッキング大会「天府杯」が公安部主導で復活 AI隆盛のさなかに https://www.nattothoughts.com/p/the-tianfu-cup-returns-under-mps ・AI生成の似顔絵をソーシャルメディアに投稿するリスク、情報セキュリティ関係者が警告 https://www.theregister.com/2026/02/11/ai_caricatures_social_media_bad_security/ <サイバー戦/APT/国家型アクター/地政学関連> ・シンガポールの大手通信企業が中国系APTの標的に ルートキットとゼロデイが悪用される https://www.securityweek.com/singapore-rootkits-zero-day-used-in-chinese-attack-on-major-telecom-firms/ ・APT36とSideCopy、インドの複数組織にクロスプラットフォームRATキャンペーンを展開 https://thehackernews.com/2026/02/apt36-and-sidecopy-launch-cross.html <逮捕/テイクダウン/制裁/違反/その他法執行関連> ・監視ツールメーカー元CEOが「数百万台のコンピューターとデバイス」にアクセス可能なエクスプロイトを露ブローカーに売却 米司法省が公訴事実と認める https://techcrunch.com/2026/02/11/doj-says-trenchant-boss-sold-exploits-to-russian-broker-capable-of-accessing-millions-of-computers-and-devices/ ・オランダ警察、MFAパスコード取得ツール「JokerOTP」の販売者を逮捕 https://www.bleepingcomputer.com/news/security/police-arrest-seller-of-jokerotp-mfa-passcode-capturing-tool/ <プライバシー> ・Google、学生ジャーナリストの個人情報と金銭関連情報をICEに提供か https://techcrunch.com/2026/02/10/google-sent-personal-and-financial-information-of-student-journalist-to-ice/ <政府/政策> ・ロシア政府がTelegramの通信速度を制限 独自のメッセージングアプリを推奨する動きに関連か https://therecord.media/russia-throttles-telegram-pushes-its-own-messaging-app

    Post summary

    The list reports several new CVEs, including a Notepad execution flaw and TDX vulnerabilities, alongside recent patch releases and evidence of active exploitation.

    00010243
    1.2K followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    CVE-2026-0488 and CVE-2026-0509 affect SAP CRM, S/4HANA, and NetWeaver ABAP. Issues allow unauthorized functionality, SQL execution, or background RFC abuse Shodan and Fofa Dorks: product:"SAP NetWeaver" title:"SAP Fiori Launchpad" https://www.thehackerwire.com/vulnerability/CVE-2026-0509 https://www.thehackerwire.com/vulnerability/CVE-2026-0488 https://t.co/VPj9sTqMXt

    Post summary

    SAP has disclosed CVE-2026-0488 and CVE-2026-0509 affecting SAP CRM, S/4HANA, and NetWeaver ABAP, which permit unauthorized functionality, SQL execution, or background RFC abuse.

    00001124
    112 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-0488 (CVSS:9.9, CRITICAL) is Undergoing Analysis. An authenticated attacker in SAP CRM and SAP S/4HANA (Scripting Editor) could exploit a flaw in a generic function modul..https://nvd.nist.gov/vuln/detail/CVE-2026-0488 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A critical CVE (CVE-2026-0488) affecting SAP CRM and S/4HANA Scripting Editor is under analysis, with a CVSS score of 9.9, but no PoC, exploit, or patch information is provided.

    0000042
    171 followersView on X
  • RagingCISO@CisoRaging77913
    Disclosure

    CVE-2026-0488: SAP CRM/S/4HANA SQL injection, CVSS 9.9. Authenticated user → arbitrary SQL → full DB compromise. SAP won't say which versions. Translation: all of them. Your million-dollar ERP still can't parameterize queries. BASIS team, coffee break's over.

    Post summary

    The post announces a severe SQL injection flaw in SAP CRM/S/4HANA, providing key technical details such as CVSS score and impact, but offers no evidence of exploitation, PoC, or patches.

    0000056
    4 followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-23687 ❗ CVE-2026-0509 ❗ CVE-2026-0488 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-sap-5/ https://t.co/yyxvzExDno

    Post summary

    The tweet lists three SAP‑related CVEs and provides links for further reading, but does not include technical details, PoC, or exploitation information.

    00000114
    6.6K followersView on X
  • Blacknuxx@Blacknuxx
    Patch

    CVE-2026-0488 9.9 SAP Security Note 3697099 was recently released and it definitely deserves some attention. We are looking at a code injection affecting both CRM and S/4HANA. https://tinyurl.com/3697099SAPCVE #SAP #SAPBasis #S4HANA #CyberSecurity #SecurityPatchDay #InfoSec

    Post summary

    SAP has released a security note for CVE‑2026‑0488, a high‑severity code injection affecting CRM and S/4HANA, but no PoC, exploit tool, or evidence of active exploitation is presented.

    000009
    215 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2026-0488 from https://vulntracker.io/cves/CVE-2026-0488

    Post summary

    The tweet merely directs readers to a vulnerability tracker page for CVE-2026-0488, offering no further information.

    0000037
    333 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: multiple critical Missing Authorization in #SAP #CRM #S4HANA #Netweaver CVE-2026-0488 & CVE-2026-0509 CVSS: 9.9-9.6 A network based attacker with low privileges can inject #SQL to compromise the database. See SAP Feb sec notes https://tinyurl.com/4xx3bavh #Patch #Patch

    Post summary

    The post warns of two critical SAP vulnerabilities (CVE‑2026‑0488 and CVE‑2026‑0509) that allow low‑privilege SQL injection, and directs readers to SAP’s February security notes for patches.

    00000223
    7.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SAP February Patch Day Fixes Critical CRM/S/4HANA SQL Injection and NetWeaver Auth Bug SAP released 27 February 2026 security notes, including two critical fixes: CVE-2026-0488 (CVSS 9.9) code injection in CRM/S/4HANA Scripting Editor enabling authenticated SQL execution, and CVE-2026-0509 (CVSS 9.6) NetWeaver missing authorization allowing low-priv users to perform background RFC calls. This matters because both issues can enable database compromise or unauthorized backend actions in high-trust SAP environments—patch urgently even though SAP didn’t note active exploitation. 🎯 Target: Global/Enterprise (SAP CRM, S/4HANA, NetWeaver) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/sap-patches-critical-crm-s-4hana-netweaver-vulnerabilities/

    Post summary

    SAP released critical security patches for CVE‑2026‑0488 and CVE‑2026‑0509, addressing SQL injection and authorization flaws. The advisory urges immediate patching to prevent potential database compromise and unauthorized backend actions.

    0000050
    191 followersView on X
  • PurpleOps@PurpleOps_io
    Patch

    🔍 𝐂𝐫𝐢𝐭𝐢𝐜𝐚𝐥 𝐒𝐀𝐏 𝐀𝐥𝐞𝐫𝐭: 𝐂𝐨𝐝𝐞 𝐈𝐧𝐣𝐞𝐜𝐭𝐢𝐨𝐧 (𝐂𝐕𝐒𝐒 𝟗.𝟗) 𝐄𝐱𝐩𝐨𝐬𝐞𝐬 𝐒/𝟒𝐇𝐀𝐍𝐀 𝐃𝐚𝐭𝐚𝐛𝐚𝐬𝐞𝐬 • SAP released its February 2026 security update addressing 26 new vulnerabilities. • A critical code injection flaw (CVE-2026-0488, CVSS 9.9) affects SAP CRM and SAP S/4HANA. • This vulnerability allows an authenticated attacker to execute arbitrary SQL statements, risking full database compromise. SAP issued urgent security patches for a critical code injection vulnerability (CVSS 9.9) in S/4HANA and CRM that could enable full database compromise.

    Post summary

    SAP has released urgent patches for a critical code injection vulnerability (CVE‑2026‑0488) that allows authenticated attackers to run arbitrary SQL on S/4HANA and CRM, potentially compromising databases.

    00000100
    64 followersView on X
  • VulDB 🛡@vuldb
    Disclosure

    A severe vulnerability was disclosed for SAP CRM and S4HANA (CVE-2026-0488) https://vuldb.com/?id.345163

    Post summary

    A severe SAP CRM and S4HANA vulnerability (CVE‑2026‑0488) has been disclosed, with details available via the referenced Vuldb link.

    0000096
    2.1K followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL SAP flaw: CVE-2026-0488 lets attackers bypass auth in SAP CRM & S/4HANA Scripting Editor, risking full DB compromise. Patch ASAP, restrict access! https://radar.offseq.com/threat/cve-2026-0488-cwe-862-missing-authorization-in-sap-cae5a650 #OffSeq #SAP #Vulnerability https://t.co/6qrRNGFaWH

    Post summary

    A critical SAP flaw (CVE-2026-0488) that allows authentication bypass in SAP CRM and S/4HANA Scripting Editor, potentially compromising the database, has been disclosed and an urgent patch is recommended.

    0000075
    268 followersView on X
CPE platform detail18 entries

18 of 18 entries

PartVendorProductVersionTarget SWTarget HW
Appsapnetweaver_application_server_abap700--
Appsaps\/4hana102--
Appsaps\/4hana103--
Appsaps\/4hana104--
Appsaps\/4hana105--
Appsaps\/4hana106--
Appsaps\/4hana107--
Appsaps\/4hana108--
Appsaps\/4hana109--
Appsapwebclient_ui_framework700--
Appsapwebclient_ui_framework701--
Appsapwebclient_ui_framework730--
Appsapwebclient_ui_framework731--
Appsapwebclient_ui_framework746--
Appsapwebclient_ui_framework747--
Appsapwebclient_ui_framework748--
Appsapwebclient_ui_framework800--
Appsapwebclient_ui_framework801--

Explore more