logo

Critical SAP Alert: Code Injection (CVSS 9.9) Exposes S/4HANA Databases

ID: 65e2cf42-875c-5d8c-b3a9-ef81533cbbd0

STIX ID: report--65e2cf42-875c-5d8c-b3a9-ef81533cbbd0

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-02-10

Date Updated: 2026-04-23

Author: Ddos

...
...

SAP published its February 2026 security update fixing 26 vulnerabilities across its enterprise ecosystem. The most severe is CVE-2026-0488, a code injection flaw in the Scripting Editor for SAP CRM and SAP S/4HANA (CVSS 9.9) that could allow authenticated attackers to execute arbitrary SQL and fully compromise databases. Other notable fixes include a missing authorization in SAP NetWeaver Application Server ABAP (CVE-2026-0509, CVSS 9.6), an XML Signature Wrapping issue in NetWeaver (CVE-2026-23687, CVSS 8.8), multiple DoS vulnerabilities, a race condition in Commerce Cloud, and an open redirect in BI Platform; administrators are urged to apply Security Note 3697099 promptly.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.