A Critical SAP Commerce Cloud Flaw is Being Exploited Just Three Days After Patch Release
A maximum-severity vulnerability in SAP’s Commerce Cloud e-commerce platform, patched just three days ago, has already been targeted by attackers. The critical flaw, tracked as CVE-2026-58231, allows unauthenticated attackers to execute arbitrary code with ease, compromising the confidentiality, integrity, and availability of the application.
SAP Commerce Cloud is a cloud-based e-commerce solution used by high-profile global brands and large retailers worldwide. According to threat intelligence company Defused, the vulnerability stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud. Attackers can exploit this flaw with low complexity, submitting specially crafted input to functions that lack sufficient validation.
SAP has issued a security advisory warning of the potential impact of successful exploitation, which could enable arbitrary code execution and compromise internal components. While SAP has not yet flagged the vulnerability as actively exploited, Defused researchers have confirmed that CVE-2026-58231 is being targeted in the wild. “First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots – 3 days after patch day,” Defused warned on Twitter.
SAP has released a security note for customers and partners, recommending that they patch their systems immediately to mitigate the vulnerability. The company is also investigating the issue. However, with over 4,200 IP addresses associated with SAP Commerce Cloud tracked by Shadowserver, there is a significant risk of unpatched systems being compromised.
This latest development highlights the importance of timely patching and adherence to security best practices. SAP has recently released patches for multiple vulnerabilities affecting its e-commerce platform, including three critical flaws in June and May. The company’s July 2026 Security Patch package fixed 16 vulnerabilities, emphasizing the need for continued vigilance and prompt action.
For users of SAP Commerce Cloud, it is essential to prioritize patching and ensure that all systems are up-to-date with the latest security patches. As seen in this case, even a few days’ delay can be exploited by attackers. By taking proactive steps to secure their systems, organizations can minimize the risk of exploitation and protect their sensitive data.
In light of this vulnerability, we urge all SAP Commerce Cloud users to review their patching schedules and implement the latest security patches without delay.
Source: Bleeping Computer — 2026-08-14