CVE-2026-24328General(sap / business_server_pages)

MEDIUMCVSS 6.1 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch sap business_server_pages systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

SAP TAF_APPLAUNCHER within Business Server Pages allows unauthenticated attacker to craft malicious links that, when clicked by a victim, redirect them to attacker?controlled sites, potentially exposing or altering sensitive information in the victim�s browser. This results in a low impact on confidentiality and integrity, with no impact on the availability of the application.

5.5/ 10 priority

Sources & remediation

Vendor / third-party advisories
Weakness type (CWE)
CWE-601

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • business_server_pages

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 2 mentions across 2 observed days

What's happening

  • Active exploitation reported across 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-02-10); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
business_server_pages

4 versions affected across 1 product

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-10: 1Mentions · 2026-02-13: 1PoC Mentioned / Linked · 2026-02-13: 1Active Exploitation · 2026-02-13: 1Patch / Workaround · 2026-02-13: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-13: 102-1002-13
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-02-101
General1
2026-02-131
Patch1
Full discourse2 posts
  • Ostorlab@OstorlabSec
    Patch

    🚨 CVE-2026-24328: SAP BSP TAF_APPLAUNCHER Open Redirect Vulnerability 🚨 A medium-severity open redirect flaw in SAP Business Server Pages (BSP) allows unauthenticated attackers to redirect legitimate SAP users to attacker-controlled domains. Public PoC available with active phishing exploitation patterns observed. Risk Severity: Medium (CVSS 6.1, unauthenticated, phishing weaponization, high operational risk) Impact: Phishing campaigns using trusted SAP domains Enterprise credential harvesting Malware delivery via redirected URLs Brand impersonation & trust abuse Initial access vector into corporate environments Root Cause: CWE-601 (Open Redirect) – Improper validation of user-supplied redirect parameters in the TAF_APPLAUNCHER component allows domain allowlist bypass via encoding and malformed URL schemes. Attackers can: Redirect SAP users to malicious external websites Harvest enterprise credentials Deliver malware payloads Exploit user trust in SAP-branded URLs Are You Affected? Vulnerable: SAP NetWeaver AS ABAP SAP_BASIS 7.50 – 7.57 SAP_BASIS 7.77 – 7.86 Fixed in: SAP_BASIS 7.58 SAP_BASIS 7.87 February 2026 SAP Patch Day updates Immediate Action Required: Update/Patch: Apply SAP Security Note from February 2026 Patch Day immediately Mitigation (if patching is delayed): Block external redirects using SAP ICM filtering Deploy WAF rules blocking redirect_url parameters Restrict access to /sap/bc/bsp endpoints Disable TAF_APPLAUNCHER if not business-critical Audit & Monitor: Hunt for HTTP 302 responses from /taf_applauncher Monitor for suspicious redirect_url parameters Analyze proxy logs for SAP-originated external redirects Alert on SAP portal traffic leading to newly registered domains SAP portals are highly trusted — this vulnerability enables extremely convincing phishing attacks, making it a prime enterprise breach vector. Patch urgently. 🔐 #ostorlabCVE

    Post summary

    CVE‑2026‑24328 is a medium‑severity open‑redirect flaw in SAP BSP that is already being exploited in phishing campaigns. SAP has released a patch in the February 2026 Patch Day, with additional mitigations and monitoring recommendations.

    0000089
    581 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-24328 SAP Business Server Pages Cross-Site Redirection in TAF_APPLAUNCHER Vulnerability https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-24328

    Post summary

    The text merely references CVE‑2026‑24328 with a link, lacking any detailed exploitation, patch, or active‑use information.

    0000068
    4.0K followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appsapbusiness_server_pages2008_1_700--
Appsapbusiness_server_pages2008_1_710--
Appsapbusiness_server_pages740--
Appsapbusiness_server_pages758--

Explore more