TL;DR: SAP’s February 2026 Patch Day includes 26 security notes, with two Critical issues in CRM scripting and RFC authorization enforcement, plus high-risk defects in BusinessObjects and XML signature handling, according to Pathlock. The pattern is clear: trusted SAP execution paths are still where access control, identity trust, and availability break first.
Editorial analysis by NHI Mgmt Group, based on content published by Pathlock: “SAP Patch Day February 2026 | Action Required for CVEs”.
By the numbers:
- SAP’s February 2026 Patch Day includes 26 SAP Security Notes.
Key questions
Q: What breaks when SAP authorisation checks fail in RFC paths?
A: When RFC checks fail, a low-privileged authenticated user can trigger remote-enabled operations that were meant to be blocked.
Q: Why do trusted SAP execution paths create such high risk after authentication?
A: Because authentication does not equal authorization depth.
Q: What are the most important signs that SAP trust boundaries are too wide?
A: Look for privileged admin roles that are shared, RFC destinations that are callable from many systems, scheduler hosts with direct network exposure, and patch fixes that are applied but not verified in production.
Practitioner guidance
- Patch the CRM scripting and RFC notes first Prioritise the CRM / S/4HANA Scripting Editor and RFC authorization enforcement corrections before lower-impact defects because both can convert authenticated access into unauthorized execution.
- Disable legacy scripting exposure where possible If the legacy CRM Scripting Editor is not required, remove or disable the SICF service so the vulnerable path is not reachable during the patch window.
- Review S_RFC and trusted RFC destinations Audit which users, service accounts and integrations can invoke RFC-enabled functions, then reduce trusted destinations and broad S_RFC assignments to the minimum needed.
Bottom line: The February 2026 SAP Patch Day is fundamentally about trust-boundary failures in control-plane paths such as CRM scripting, RFC and signed XML.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Trusted execution paths are the real SAP attack surface. The article shows that CRM scripting, RFC and signed XML are not edge cases. They are control-plane surfaces where the system still assumes trust after authentication or signature validation. That assumption is what makes low-privilege abuse so dangerous, because the attacker does not need to defeat the whole platform, only the path that the platform already trusts.
A question worth separating out:
Q: How should teams respond when SAP systems rely on trusted internal endpoints?
A: Treat them as privileged interfaces, not internal conveniences. Restrict network reachability, require backend-only communication where possible, and validate that the endpoint cannot be reached from user-facing segments. If the trust boundary is visible to ordinary users, it is already too broad.
👉 Read our full editorial: SAP February 2026 Patch Day exposes trust-boundary failures