SAP has released its February 2026 security patch package containing 27 security notes addressing critical vulnerabilities across enterprise SAP environments. This release includes two HotNews vulnerabilities with CVSS ratings up to 9.9, seven High priority issues, sixteen Medium priority fixes, and two Low priority updates. The patches affect SAP CRM, SAP S/4HANA, SAP NetWeaver, SAP BusinessObjects Business Intelligence Platform, SAP Commerce Cloud, and various application components. RedRays ABAP Code Scanner did not identify new vulnerabilities in this release cycle.
27
2
7
16
2
Executive Summary
- Critical Code Injection: CVE-2026-0488 (CVSS 9.9) in SAP CRM and SAP S/4HANA Scripting Editor allows authenticated attackers to inject and execute malicious code with cross-scope impact on confidentiality, integrity, and availability.
- Missing Authorization: CVE-2026-0509 (CVSS 9.6) in SAP NetWeaver Application Server ABAP and ABAP Platform enables authenticated users with low privileges to bypass authorization controls with cross-scope impact on integrity and availability.
- XML Signature Wrapping: CVE-2026-23687 (CVSS 8.8) in SAP NetWeaver AS ABAP and ABAP Platform allows authenticated attackers to manipulate XML signatures leading to complete system compromise.
- Multiple DoS Vulnerabilities: Seven vulnerabilities affecting SAP BusinessObjects BI Platform and SAP Supply Chain Management enable denial of service attacks with high impact on availability.
Critical HotNews Vulnerabilities
Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor)
Critical code injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor) allows authenticated attackers with low privileges to inject and execute arbitrary code. This maximum severity flaw enables complete system compromise with cross-scope impact on confidentiality, integrity, and availability of business-critical data.
Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform
Critical missing authorization check vulnerability in SAP NetWeaver Application Server ABAP and ABAP Platform allows authenticated users with low privileges to bypass authorization controls and perform unauthorized actions. Successful exploitation leads to cross-scope impact with high severity on system integrity and availability.
High Priority Security Issues
XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform
High severity XML Signature Wrapping vulnerability in SAP NetWeaver AS ABAP and ABAP Platform allows authenticated attackers to manipulate XML signatures. Successful exploitation leads to complete compromise of confidentiality, integrity, and availability of affected systems.
Missing Authorization check in SAP Solution Tools Plug-In (ST-PI)
Missing authorization check in SAP Solution Tools Plug-In (ST-PI) allows authenticated attackers to access sensitive system information with cross-scope impact. High severity vulnerability affecting confidentiality of system data.
Denial of service (DOS) in SAP Supply Chain Management
Denial of service vulnerability in SAP Supply Chain Management allows authenticated attackers to disrupt service availability with cross-scope impact. High severity threat to business continuity and supply chain operations.
Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform
Unauthenticated denial of service vulnerability in SAP BusinessObjects BI Platform enables remote attackers to disrupt business intelligence services without authentication, causing high impact on system availability.
Denial of service (DOS) in SAP BusinessObjects BI Platform
Additional unauthenticated denial of service vulnerability in SAP BusinessObjects BI Platform allows remote attackers to disrupt reporting and analytics services with high availability impact.
Race Condition in SAP Commerce Cloud
Race condition vulnerability in SAP Commerce Cloud allows unauthenticated attackers to exploit timing windows and compromise confidentiality and integrity of e-commerce operations under complex attack conditions.
Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform
Open redirect vulnerability in SAP BusinessObjects Business Intelligence Platform allows high-privileged attackers to redirect users to malicious sites with cross-scope impact on confidentiality and integrity under complex attack conditions.
Medium Priority Vulnerabilities
Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform (AdminTools)
Denial of service vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools) allows authenticated attackers to disrupt administrative functions with high impact on system availability.
Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA
Missing authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA allows authenticated attackers to modify system data with high impact on integrity.
Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER)
Open redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER) allows unauthenticated attackers to redirect users to malicious sites with cross-scope impact on confidentiality and integrity.
Multiple vulnerabilities in BSP Applications of SAP Document Management System
Multiple security vulnerabilities in BSP Applications of SAP Document Management System allow unauthenticated attackers to compromise document security with cross-scope impact.
Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML)
Information disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) allows high-privileged local attackers to access sensitive system information with cross-scope impact.
Race condition vulnerability in SAP Commerce Cloud
Race condition vulnerability in SAP Commerce Cloud allows unauthenticated attackers to exploit timing windows and compromise integrity of e-commerce transactions under complex attack conditions.
Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files)
Information disclosure vulnerability in SAP Business One (B1 Client Memory Dump Files) allows high-privileged local attackers to access sensitive business data from memory dump files.
Information Disclosure vulnerability in SAP Commerce Cloud
Information disclosure vulnerability in SAP Commerce Cloud allows unauthenticated attackers to access sensitive e-commerce information with low confidentiality impact.
Missing authorization check in SAP Business Workflow
Missing authorization check in SAP Business Workflow allows high-privileged attackers to bypass authorization controls and modify workflow data with user interaction.
Missing Authorization Check in ABAP based SAP systems
Missing authorization check in ABAP based SAP systems allows authenticated attackers to access sensitive system information with cross-scope impact on confidentiality.
Cross Site Scripting (XSS) vulnerability in SAP BusinessObjects Enterprise (Central Management Console)
Cross-Site Scripting vulnerability in SAP BusinessObjects Enterprise (Central Management Console) allows high-privileged attackers to inject malicious scripts with cross-scope impact.
Insecure Deserialization vulnerability in SAP NetWeaver (JMS service)
Insecure deserialization vulnerability in SAP NetWeaver (JMS service) allows high-privileged local attackers to cause denial of service with high availability impact.
Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application)
Missing authorization check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application) allows authenticated attackers to access sensitive strategic management data.
Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations)
Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations) allows authenticated attackers to modify defense and security data with low integrity impact.
Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services)
Missing authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services) allows authenticated attackers to modify service entry data with low integrity impact.
Missing Authorization check in a function module in SAP Support Tools Plug-In
Missing authorization check in a function module in SAP Support Tools Plug-In allows authenticated attackers to access sensitive support tool data with low confidentiality impact.
Low Priority Security Updates
CRLF Injection vulnerability in SAP NetWeaver Application Server Java
CRLF injection vulnerability in SAP NetWeaver Application Server Java allows high-privileged attackers to inject CRLF sequences with cross-scope impact on integrity under user interaction conditions.
Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP)
Memory corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP) allows authenticated attackers to trigger memory corruption with limited confidentiality impact under complex attack conditions.
Security Advisory prepared by RedRays Cybersecurity Team
Based on SAP Security Notes published 10 February 2026.
© 2026 RedRays. Test patches in development environments before production deployment.




