【Security Advisory】SAP Releases Critical Security Advisory for Multiple Products_260212

publish date : 2026-02-24 update date : 2026-02-24

Source: Ministry of education information & communication security contingency platform

"" "" ""

Publication Number TACERT-ANA-2026021204023232 Publication Time 2026/02/12 16:47
Incident Type ANA-Vulnerability Alert Discovery Time 2026/02/12 16:47
Impact Level Low  
[Subject]
【Security Advisory】SAP Releases Critical Security Advisory for Multiple Products

[Content]
Forwarded from TWCERTCC-200-202602-00000008

【CVE-2026-23687, CVSS: 8.8】 This vulnerability exists in SAP NetWeaver AS ABAP and ABAP Platform. It allows an authenticated attacker with normal privileges to obtain valid signature information and send an updated signed XML document to the verification endpoint for validation.

【CVE-2026-0509, CVSS: 9.6】 This vulnerability exists in SAP NetWeaver AS ABAP and ABAP Platform. It allows an authenticated low-privileged attacker to execute backend Remote Function Calls (RFC) without obtaining S_RFC authorization.

【CVE-2026-0488, CVSS: 9.9】 An authenticated attacker may exploit a generic function module call vulnerability in SAP CRM and SAP S/4HANA (Script Editor) to execute unauthorized critical functions, including the execution of arbitrary SQL statements."

(Information Sharing Level: WHITE (Information content can be publicly disclosed)

[Affected Platform]
SAP NetWeaver Application Server ABAP and ABAP Platform Version(s) - KRNL64NUC 7.22, 7.22EXT, KRNL64UC 7.22, 7.22EXT, 753, KERNEL 7.22, 7.53, 7.54, 7.77, 7.89, 7.93, 9.16, 9.18, 9.19 

SAP CRM and SAP S/4HANA (Scripting Editor) Version(s) - S4FND 102, 103, 104, 105, 106, 107, 108, 109, SAP_ABA 700, WEBCUIF 700, 701, 730, 731, 746, 747, 748, 800, 801 

SAP NetWeaver AS ABAP and ABAP Platform Version(s) - SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, SAP_BASIS 740, SAP_BASIS 750, SAP_BASIS 751, SAP_BASIS 752, SAP_BASIS 753, SAP_BASIS 754, SAP_BASIS 755, SAP_BASIS 756, SAP_BASIS 757, SAP_BASIS 758, SAP_BASIS 804, SAP_BASIS 916, SAP_BASIS 917, SAP_BASIS 918"

[Recommended Actions]
Apply remediation in accordance with the solutions released on the official website:

https://support.sap.com/en/my-support/knowledge-base/security-notes-news/february-2026.html

[Reference]
https://www.twcert.org.tw/tw/cp-169-10717-00173-1.html
(This notification is for informational purposes only and does not constitute a cybersecurity incident).
If you have questions or suggestions regarding this notification, please feel free to contact us.
Ministry of education information & communication security contingency platform
Website: https://info.cert.tanet.edu.tw/
Phone: +886-7-5250211
Internet Phone: 98400000
E-Mail: service@cert.tanet.edu.tw
Organizer: Computer Center