Critical SAP Alert: Code Injection (CVSS 9.9) Exposes S/4HANA Databases
ID: 65e2cf42-875c-5d8c-b3a9-ef81533cbbd0
STIX ID: report--65e2cf42-875c-5d8c-b3a9-ef81533cbbd0
Feed Name: securityonline.info
SAP published its February 2026 security update fixing 26 vulnerabilities across its enterprise ecosystem. The most severe is CVE-2026-0488, a code injection flaw in the Scripting Editor for SAP CRM and SAP S/4HANA (CVSS 9.9) that could allow authenticated attackers to execute arbitrary SQL and fully compromise databases. Other notable fixes include a missing authorization in SAP NetWeaver Application Server ABAP (CVE-2026-0509, CVSS 9.6), an XML Signature Wrapping issue in NetWeaver (CVE-2026-23687, CVSS 8.8), multiple DoS vulnerabilities, a race condition in Commerce Cloud, and an open redirect in BI Platform; administrators are urged to apply Security Note 3697099 promptly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
