SAP’s February 2026 Security Patch Day shipped 26 new SAP Security Notes (plus one updated note) and urged customers to prioritize patching across core SAP workloads. The most severe issue is CVE-2026-0488 (CVSS 9.9), a code-injection vulnerability in the Scripting Editor of SAP CRM and SAP S/4HANA (SAP Note 3697099), which can be exploited by an authenticated, low-privilege user to execute arbitrary code/unauthorized functionality with broad impact across the environment.
The bulletin also addressed additional critical and high-severity risks, including CVE-2026-0509 (CVSS 9.6; SAP Note 3674774), a missing authorization check in SAP NetWeaver Application Server ABAP / ABAP Platform that can allow low-privilege users to perform unauthorized actions (including background RFC activity). Other highlighted items include CVE-2026-23687 (XML Signature Wrapping) affecting trust decisions in XML-based flows, and CVE-2026-23689 in SAP Supply Chain Management, an uncontrolled resource consumption issue that can be abused to cause denial of service by exhausting system resources via repeated calls with oversized parameters.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
On 2026-02-10, the Canadian Centre for Cyber Security published advisory AV26-107 summarizing SAP's February 2026 Security Patch Day. The agency highlighted affected SAP products, explicitly referenced CVE-2026-0488 and CVE-2026-0509, and urged administrators to review SAP advisories and deploy mitigations and updates.
The same February 2026 patch cycle also fixed other notable issues, including CVE-2026-23687, an XML Signature Wrapping flaw in SAP NetWeaver trust verification, and CVE-2026-23689, a denial-of-service issue in SAP Supply Chain Management. Additional patches covered DoS, race condition, open redirect, XSS, insecure deserialization, information disclosure, and authorization weaknesses in products such as SAP BusinessObjects, SAP Commerce Cloud, SAP Document Management System, and SAP Fiori apps.
On 2026-02-10, SAP also remediated CVE-2026-0509, a critical missing authorization check in SAP NetWeaver Application Server ABAP / ABAP Platform rated CVSS 9.6. The issue could let low-privileged authenticated users bypass controls and perform unauthorized background RFC actions, affecting integrity and availability.
As part of the 2026-02-10 patch release, SAP fixed CVE-2026-0488, a critical code injection flaw in the Scripting Editor of SAP CRM and SAP S/4HANA rated CVSS 9.9. The vulnerability could allow an authenticated low-privilege attacker to execute arbitrary SQL or code and potentially fully compromise the database.
On 2026-02-10, SAP published its February 2026 Security Patch Day updates, releasing 26 new security notes and one update affecting multiple products including SAP CRM, SAP S/4HANA, SAP NetWeaver, SAP Supply Chain Management, SAP BusinessObjects, and SAP Commerce Cloud. The release included fixes for critical, high, and medium-severity vulnerabilities and urged customers to apply updates promptly.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
cyber.gc.ca
Open sourcecybersecuritynews.com
Open sourcesecurityonline.info
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.