SAP NetWeaver Application Server ABAP Vulnerability Allowing Unauthorized Remote Function Calls
CVE-2026-0509

9.6CRITICAL

Key Information:

Vendor

SAP

Vendor
CVE Published:
10 February 2026

What is CVE-2026-0509?

A security flaw in the SAP NetWeaver Application Server ABAP and ABAP Platform permits an authenticated, low-privileged user to execute background Remote Function Calls without the necessary S_RFC authorization under certain circumstances. This oversight may lead to significant impacts on the integrity and availability of the systems involved, while the confidentiality of the application remains unaffected.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

SAP NetWeaver Application Server ABAP and ABAP Platform KRNL64NUC 7.22

SAP NetWeaver Application Server ABAP and ABAP Platform 7.22EXT

SAP NetWeaver Application Server ABAP and ABAP Platform KRNL64UC 7.22

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.