
🚨 CVE-2026-24328: SAP BSP TAF_APPLAUNCHER Open Redirect Vulnerability 🚨 A medium-severity open redirect flaw in SAP Business Server Pages (BSP) allows unauthenticated attackers to redirect legitimate SAP users to attacker-controlled domains. Public PoC available with active phishing exploitation patterns observed. Risk Severity: Medium (CVSS 6.1, unauthenticated, phishing weaponization, high operational risk) Impact: Phishing campaigns using trusted SAP domains Enterprise credential harvesting Malware delivery via redirected URLs Brand impersonation & trust abuse Initial access vector into corporate environments Root Cause: CWE-601 (Open Redirect) – Improper validation of user-supplied redirect parameters in the TAF_APPLAUNCHER component allows domain allowlist bypass via encoding and malformed URL schemes. Attackers can: Redirect SAP users to malicious external websites Harvest enterprise credentials Deliver malware payloads Exploit user trust in SAP-branded URLs Are You Affected? Vulnerable: SAP NetWeaver AS ABAP SAP_BASIS 7.50 – 7.57 SAP_BASIS 7.77 – 7.86 Fixed in: SAP_BASIS 7.58 SAP_BASIS 7.87 February 2026 SAP Patch Day updates Immediate Action Required: Update/Patch: Apply SAP Security Note from February 2026 Patch Day immediately Mitigation (if patching is delayed): Block external redirects using SAP ICM filtering Deploy WAF rules blocking redirect_url parameters Restrict access to /sap/bc/bsp endpoints Disable TAF_APPLAUNCHER if not business-critical Audit & Monitor: Hunt for HTTP 302 responses from /taf_applauncher Monitor for suspicious redirect_url parameters Analyze proxy logs for SAP-originated external redirects Alert on SAP portal traffic leading to newly registered domains SAP portals are highly trusted — this vulnerability enables extremely convincing phishing attacks, making it a prime enterprise breach vector. Patch urgently. 🔐 #ostorlabCVE
Post summary
CVE‑2026‑24328 is a medium‑severity open‑redirect flaw in SAP BSP that is already being exploited in phishing campaigns. SAP has released a patch in the February 2026 Patch Day, with additional mitigations and monitoring recommendations.

