cbcvebase.
CVE-2026-0509
published 2026-02-10

CVE-2026-0509: SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the…

PriorityP262critical9.6CVSS 3.1
AVNACLPRLUINSCCNIHAH
EPSS
0.34%
26.2th percentile
SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

Affected

26 ranges· showing 25
VendorProductVersion rangeFixed in
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_kernel
sapnetweaver_as_abap_krnl64nuc
sapnetweaver_as_abap_krnl64nuc
sapnetweaver_as_abap_krnl64uc
sapnetweaver_as_abap_krnl64uc
sapnetweaver_as_abap_krnl64uc
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform
sap_sesap_netweaver_application_server_abap_and_abap_platform

Detection & IOCsextracted from sources · hover to see the quote

  • Monitor for background Remote Function Calls (RFC) executed by low-privileged users who lack the S_RFC authorization object — this is the core abuse primitive for CVE-2026-0509.
  • ·The vulnerability allows bypass of the S_RFC authorization check in certain cases; ensure S_RFC authorization objects are correctly assigned and audit all RFC-enabled function modules accessible to low-privileged users.
  • ·Impact is limited to integrity and availability — confidentiality is not affected — but the CVSS score is 9.6 (CRITICAL), indicating the integrity/availability impact is severe.
  • ·A fix was made available on February 11, 2026 for both Linux and Windows deployments of SAP NetWeaver Application Server ABAP.
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.