Max severity SAP Commerce Cloud flaw now targeted in attacks

A Critical SAP Commerce Cloud Flaw is Being Exploited in Real-World Attacks, Just Days After Patch Release

A maximum-severity vulnerability in SAP’s Commerce Cloud platform has been targeted by attackers just three days after the company released a patch to fix it. The flaw, tracked as CVE-2026-58231, allows an unauthenticated attacker to execute arbitrary code on affected systems, potentially compromising confidentiality, integrity, and availability.

SAP Commerce Cloud is a cloud-based e-commerce platform used by many high-profile global brands and large retailers. The platform’s Data Hub Adapter extension was found to have an improper authorization weakness that could be exploited in low-complexity attacks. SAP has confirmed that the vulnerability can lead to arbitrary code execution, which would give attackers complete control over affected systems.

According to threat intelligence firm Defused, their honeypots are now being hit with exploitation attempts against CVE-2026-58231. While SAP has not yet flagged this as actively exploited in a security advisory, it’s clear that the vulnerability is being targeted by malicious actors. “First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day,” Defused warned on Twitter.

SAP has taken steps to address the issue, releasing a security note and urging customers to patch their systems immediately. However, it’s not clear how many affected systems have already been secured against this vulnerability. Shadowserver, an internet security watchdog group, tracks over 4,200 IP addresses with a SAP Commerce Cloud fingerprint, but it’s unclear how many of these are honeypots or have already been patched.

The fact that CVE-2026-58231 has been exploited so soon after patch release highlights the importance of timely and thorough vulnerability management. SAP has released patches for multiple vulnerabilities in recent months, including three critical security flaws affecting Commerce Cloud. It’s essential for organizations using this platform to prioritize patching and take proactive steps to protect themselves against emerging threats.

As a precautionary measure, we recommend that all SAP Commerce Cloud users review their system configurations and ensure they have applied the latest patches as soon as possible. This will help prevent unauthorized access to sensitive data and minimize potential damage from exploitation attempts.


Source: Bleeping Computer — 2026-08-14