-
Non-Product Related Assistance
Request for existing cases, user IDs, Portal navigation support and more
SAP Security Patch Day - February 2026
This post shares the information on security notes that remediate vulnerabilities discovered in SAP products. SAP strongly recommends that the customer visits the Support Portal and applies patches on priority to protect their SAP landscape.
On 10th of February 2026, SAP security patch day saw the release of 26 new security notes. Further, there was 1 update to previously released Security Note.
Note# | Title | Priority | CVSS |
|---|---|---|---|
[CVE-2026-0488] Code Injection vulnerability in SAP CRM and SAP S/4HANA (Scripting Editor) Product - SAP CRM and SAP S/4HANA (Scripting Editor) | Critical | ||
[CVE-2026-0509] Missing Authorization check in SAP NetWeaver Application Server ABAP and ABAP Platform Product - SAP NetWeaver Application Server ABAP and ABAP Platform | Critical | ||
[CVE-2026-23687] XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform Product - SAP NetWeaver AS ABAP and ABAP Platform | High | ||
[CVE-2026-23689] Denial of service (DOS) in SAP Supply Chain Management Product - SAP Supply Chain Management | High | ||
[CVE-2026-24322] Missing Authorization check in SAP Solution Tools Plug-In (ST-PI) Product - SAP Solution Tools Plug-In (ST-PI) | High | ||
[CVE-2026-0490] Denial of service (DOS) in SAP BusinessObjects BI Platform Product - SAP BusinessObjects BI Platform | High | ||
[CVE-2026-0485] Denial of service (DOS) vulnerability in SAP BusinessObjects BI Platform Product - SAP BusinessObjects BI Platform | High | ||
[CVE-2025-12383] Race Condition in SAP Commerce Cloud Product - SAP Commerce Cloud | High | ||
[CVE-2026-0508] Open Redirect vulnerability in SAP BusinessObjects Business Intelligence Platform Product - SAP BusinessObjects Business Intelligence Platform | High | ||
[CVE-2026-0484] Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA Product - SAP NetWeaver Application Server ABAP and SAP S/4HANA | Medium | ||
[CVE-2026-24324] Denial of service (DOS) vulnerability in SAP BusinessObjects Business Intelligence Platform (AdminTools) Product - SAP BusinessObjects Business Intelligence Platform (AdminTools) | Medium | ||
[Multiple CVEs] Multiple vulnerabilities in BSP Applications of SAP Document Management System Additional CVE - CVE-2026-0505, CVE-2026-24323 | Medium | ||
[CVE-2026-24328] Open Redirection vulnerability in Business Server Pages Application (TAF_APPLAUNCHER) Product - Business Server Pages Application (TAF_APPLAUNCHER) | Medium | ||
Update to Security Note released on January 2025 Patch Day: [CVE-2025-0059] Information Disclosure vulnerability in SAP NetWeaver Application Server ABAP (applications based on SAP GUI for HTML) | Medium | ||
[CVE-2026-23684] Race condition vulnerability in SAP Commerce Cloud Product - SAP Commerce Cloud | Medium | ||
[CVE-2026-24319] Information Disclosure Vulnerability in SAP Business One (B1 Client Memory Dump Files) Product - SAP Business One (B1 Client Memory Dump Files) | Medium | ||
[CVE-2026-24321] Information Disclosure vulnerability in SAP Commerce Cloud Product - SAP Commerce Cloud | Medium | ||
[CVE-2026-24312] Missing authorization check in SAP Business Workflow Product - SAP Business Workflow | Medium | ||
[CVE-2026-0486] Missing Authorization Check in ABAP based SAP systems Product - ABAP based SAP systems | Medium | ||
[CVE-2026-24325] Cross Site Scripting (XSS) vulnerability in SAP BusinessObjects Enterprise (Central Management Console) Product - SAP BusinessObjects Enterprise (Central Management Console) | Medium | ||
[CVE-2026-23685] Insecure Deserialization vulnerability in SAP NetWeaver (JMS service) Product - SAP NetWeaver (JMS service) | Medium | ||
[CVE-2026-23688] Missing Authorization check in SAP Fiori App (Manage Service Entry Sheets - Lean Services) Product - SAP Fiori App (Manage Service Entry Sheets - Lean Services) | Medium | ||
[CVE-2026-23681] Missing Authorization check in a function module in SAP Support Tools Plug-In Product - SAP Support Tools Plug-In | Medium | ||
[CVE-2026-24326] Missing authorization check in SAP S/4HANA Defense & Security (Disconnected Operations) Product - SAP S/4HANA Defense & Security (Disconnected Operations) | Medium | ||
[CVE-2026-24327] Missing Authorization Check in SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application) Product - SAP Strategic Enterprise Management (Balanced Scorecard in BSP Application) | Medium | ||
[CVE-2026-23686] CRLF Injection vulnerability in SAP NetWeaver Application Server Java Product - SAP NetWeaver Application Server Java | Low | ||
[CVE-2026-24320] Memory Corruption vulnerability in SAP NetWeaver and ABAP Platform (Application Server ABAP) Product - SAP NetWeaver and ABAP Platform (Application Server ABAP) | Low |
1 new security note was released after the scheduled monthly patch day. Additionally, 4 previously released security notes were updated.
Update to Security Note released on February 2026 Patch Day: [CVE-2026-23687] XML Signature Wrapping in SAP NetWeaver AS ABAP and ABAP Platform Product - SAP NetWeaver AS ABAP and ABAP Platform | High | ||
Update to Security Note released on February 2026 Patch Day: Product - SAP BusinessObjects Business Intelligence Platform (AdminTools) | Medium | ||
Update to Security Note released on February 2026 Patch Day: [CVE-2026-0484] Missing Authorization check in SAP NetWeaver Application Server ABAP and SAP S/4HANA Product - SAP NetWeaver Application Server ABAP and SAP S/4HANA | Medium | ||
Update to Security Note released on February 2024 Patch Day: [CVE-2024-22128] Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Business Client for HTML | Medium | ||
[CVE-2026-24314] Information Disclosure vulnerability in SAP S/4HANA (Manage Payment Media) Product - S/4HANA (Manage Payment Media) | Medium |
To know more about the security researchers and research companies who have contributed for security patches of this month, visit here.
SAP is committed to delivering trustworthy products and cloud services. Secure configuration is essential to ensuring secure operation and data integrity. We have therefore documented security recommendations that are consolidated in this document to help you configure the best security for your SAP portfolio.
Archived blogs from previous years are available here.
If you have any comments or feedback about this post, you can write to secure@sap.com.