CVE-2026-0509: SAP NetWeaver As Abap Kernel

Critical severity, CVSS 9.6. EPSS: 0.4% chance of exploitation in the next 30 days.

SAP NetWeaver Application Server ABAP and ABAP Platform allows an authenticated, low-privileged user to perform background Remote Function Calls without the required S_RFC authorization in certain cases. This can result in a high impact on integrity and availability, and no impact on the confidentiality of the application.

Affected products

  • SAP NetWeaver As Abap Kernel: version 7.22 only; version 7.53 only; version 7.54 only; version 7.77 only; version 7.89 only; version 7.93 only; …
  • SAP NetWeaver As Abap KRNL64NUC: version 7.22 only; version 7.22ext only
  • SAP NetWeaver As Abap KRNL64UC: version 7.22 only; version 7.22ext only; version 7.53 only

Published 2026-02-10. Last modified 2026-06-17.