CVE-2026-0509Patch(sap / netweaver_as_abap_kernel)

LOWCVSS 9.6 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch sap netweaver_as_abap_kernel systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

0.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • netweaver_as_abap_kernel
  • netweaver_as_abap_krnl64nuc
  • netweaver_as_abap_krnl64uc

Threat summary

  • Patch or workaround signal is available
  • 10 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 7 signals
  • Technical details provided in 8 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 6 mentions (2026-02-10); latest day: 1
  • 10 total mentions across 4 days

Affected systems

Vendors
Products
netweaver_as_abap_kernelnetweaver_as_abap_krnl64nucnetweaver_as_abap_krnl64uc

10 versions affected across 3 products

Deep dive

Activity timeline10 mentions / 4d
02356Mentions · 2026-02-10: 6Mentions · 2026-02-12: 2Mentions · 2026-02-15: 1Mentions · 2026-02-18: 1Patch / Workaround · 2026-02-10: 5Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-18: 1Technical Details · 2026-02-10: 6Technical Details · 2026-02-15: 1Technical Details · 2026-02-18: 102-1002-1202-1502-18
Signal classification2 categories
Patch
770.0%
Disclosure
330.0%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-106
Disclosure1Patch5
2026-02-122
Disclosure1Patch1
2026-02-151
Disclosure1
2026-02-181
Patch1
Full discourse10 posts
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SAP February Patch Day Fixes Critical Code Injection in CRM/S/4HANA and NetWeaver Auth Flaw SAP’s February 10, 2026 patch day shipped 26 new notes + 1 update, led by CVE-2026-0488 (CVSS 9.9) code injection in SAP CRM/S/4HANA Scripting Editor and CVE-2026-0509 (CVSS 9.6) missing authorization in NetWeaver AS ABAP/ABAP Platform—both enabling low-priv authenticated users to escalate into high-impact compromise. Additional fixes include XML Signature Wrapping and multiple DoS/redirect issues across SAP components, so SAP landscapes should prioritize patching and reduce exposure of user-facing endpoints. 🎯 Target: Global/Enterprise (SAP) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://cybersecuritynews.com/sap-security-patch-day-feburary/

    Post summary

    The article announces SAP’s February 10, 2026 patch day, detailing critical CVEs for code injection and missing authorization, and urges customers to apply the released patches to mitigate risk.

    0000277
    191 followersView on X
  • Autumn Good@autumn_good_35
    Patch

    新規のCriticalが2件 [CVE-2026-0488] Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor) [CVE-2026-0509] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform SAP Security Patch Day - February 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2026.html

    Post summary

    Two new critical SAP CVEs were disclosed with an associated Security Patch Day and a link to SAP’s support site for remediation.

    10010716
    6.7K followersView on X
  • iototsecnews@iototsecnews
    Patch

    SAP の脆弱性 CVE-2026-0488/0509/23687 などが FIX:CRM や S/4HANA にコード・インジェクションの恐れ https://iototsecnews.jp/2026/02/10/sap-security-patch-day-fixes-critical-code-injection-flaw-in-sap-crm-and-s-4hana/ SAP の 2026年2月10日の Patch Day で、複数の脆弱性が修正されました。その中で、最も深刻なものは、SAP CRM や S/4HANA のスクリプト編集機能 (Scripting Editor) における、入力されたプログラム・コードに対する不十分な検証の脆弱性 CVE-2026-0488 (CVSS:9.9) です。本来は限られた操作しかできないはずの低権限ユーザーであっても、この脆弱性を悪用することでコード・インジェクションを引き起こし、システム内部で命令を実行できてしまいます。また、脆弱性 CVE-2026-0509 (CVSS:9.6) も、認可チェックの欠如により、権限を越えた操作を許してしまう危険なものです。ご利用のチームは、ご注意ください。 #CVE202512383 #CVE20260485 #CVE20260488 #CVE20260490 #CVE20260508 #CVE20260509 #CVE202623687 #CVE202623689 #CVE202624322 #PatchTuesday #SAP #Vulnerability

    Post summary

    The post reports SAP’s Patch Day that addresses critical code‑injection flaws (CVE‑2026‑0488, CVE‑2026‑0509) with high CVSS scores; teams should apply the updates promptly.

    01000145
    484 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    CVE-2026-0488 and CVE-2026-0509 affect SAP CRM, S/4HANA, and NetWeaver ABAP. Issues allow unauthorized functionality, SQL execution, or background RFC abuse Shodan and Fofa Dorks: product:"SAP NetWeaver" title:"SAP Fiori Launchpad" https://www.thehackerwire.com/vulnerability/CVE-2026-0509 https://www.thehackerwire.com/vulnerability/CVE-2026-0488 https://t.co/VPj9sTqMXt

    Post summary

    The text announces CVE-2026-0488 and CVE-2026-0509 affecting SAP products, outlining the vulnerability types but providing no PoC, exploit code, or patch information.

    00001124
    112 followersView on X
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-0509 (CVSS:9.6, CRITICAL) is Undergoing Analysis. SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform backgrou..https://nvd.nist.gov/vuln/detail/CVE-2026-0509 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    A critical vulnerability (CVSS 9.6) in SAP NetWeaver Application Server ABAP is under analysis, permitting authenticated low‑privileged users to exploit a background issue.

    0000031
    171 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidades en productos SAP ❗ CVE-2026-23687 ❗ CVE-2026-0509 ❗ CVE-2026-0488 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-sap-5/ https://t.co/yyxvzExDno

    Post summary

    The post announces three new CVE identifiers affecting SAP products and provides links for additional information.

    00000114
    6.6K followersView on X
  • Blacknuxx@Blacknuxx
    Patch

    [CVE-2026-0509 9.6] Security Bypass in the ABAP Core. Kernel Update https://www.linkedin.com/pulse/cve-2026-0509-96-security-bypass-abap-core-kernel-update-claret-me7kf

    Post summary

    The post announces a kernel update intended to patch the security bypass identified by CVE-2026-0509 in ABAP Core.

    000005
    215 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: multiple critical Missing Authorization in #SAP #CRM #S4HANA #Netweaver CVE-2026-0488 & CVE-2026-0509 CVSS: 9.9-9.6 A network based attacker with low privileges can inject #SQL to compromise the database. See SAP Feb sec notes https://tinyurl.com/4xx3bavh #Patch #Patch

    Post summary

    SAP's CVE-2026-0488 and CVE-2026-0509 involve missing authorization that allows SQL injection; patches are available in the February security notes.

    00000223
    7.2K followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 SAP February Patch Day Fixes Critical CRM/S/4HANA SQL Injection and NetWeaver Auth Bug SAP released 27 February 2026 security notes, including two critical fixes: CVE-2026-0488 (CVSS 9.9) code injection in CRM/S/4HANA Scripting Editor enabling authenticated SQL execution, and CVE-2026-0509 (CVSS 9.6) NetWeaver missing authorization allowing low-priv users to perform background RFC calls. This matters because both issues can enable database compromise or unauthorized backend actions in high-trust SAP environments—patch urgently even though SAP didn’t note active exploitation. 🎯 Target: Global/Enterprise (SAP CRM, S/4HANA, NetWeaver) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.securityweek.com/sap-patches-critical-crm-s-4hana-netweaver-vulnerabilities/

    Post summary

    SAP issued urgent patches for CVE-2026-0488 and CVE-2026-0509, both with high CVSS scores, and highlighted the risks without evidence of active exploitation.

    0000050
    191 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: SAP NetWeaver ABAP flaw lets low-priv users run unauthorized background RFCs — risking integrity & availability! Patch ASAP, restrict permissions, monitor logs. Affects versions 7.22 – 9.19. https://radar.offseq.com/threat/cve-2026-0509-cwe-862-missing-authorizatio... https://t.co/KCq1TKoeW3

    Post summary

    SAP NetWeaver ABAP vulnerability lets low‑privileged users execute unauthorized background RFCs; patch immediately and tighten permissions.

    0000060
    268 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
Appsapnetweaver_as_abap_kernel7.22--
Appsapnetweaver_as_abap_kernel7.53--
Appsapnetweaver_as_abap_kernel7.54--
Appsapnetweaver_as_abap_kernel7.77--
Appsapnetweaver_as_abap_kernel7.89--
Appsapnetweaver_as_abap_kernel7.93--
Appsapnetweaver_as_abap_kernel9.16--
Appsapnetweaver_as_abap_kernel9.18--
Appsapnetweaver_as_abap_kernel9.19--
Appsapnetweaver_as_abap_krnl64nuc7.22--
Appsapnetweaver_as_abap_krnl64nuc7.22ext--
Appsapnetweaver_as_abap_krnl64uc7.22--
Appsapnetweaver_as_abap_krnl64uc7.22ext--
Appsapnetweaver_as_abap_krnl64uc7.53--

Explore more