started · updated
SAP Commerce Cloud vulnerability under active exploitation
Threat actors have begun actively exploiting a critical vulnerability in SAP Commerce Cloud, identified as CVE-2026-58231. The flaw carries a maximum CVSS severity score of 10.0 and allows unauthenticated attackers to achieve remote code execution (RCE) by abusing a default authentication client and exploiting insufficient input validation within the Data Hub Adapter.
Security researchers at Defused Cyber reported observing the first wave of exploitation attempts in honeypots just three days after SAP released official security patches. Despite the active targeting, there is currently no public proof of concept (PoC) available, suggesting that attackers may have reverse-engineered the vendor's fix to develop their methods.
Successful exploitation could grant attackers full administrative control over backend databases, transaction pipelines, and sensitive enterprise assets, impacting the confidentiality, integrity, and availability of global digital storefronts and supply chain operations. Security firm Onapsis recommends that affected organizations immediately migrate to a fixed Commerce Cloud release. For those unable to patch immediately, implementing an IP Filter Set to restrict access to the vulnerable endpoint is suggested as a temporary mitigation.
Entities
Charlotte Colocation Center · Defused Cyber · Onapsis · SAP · Shadowserver
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 2 SOURCES] There is currently no public proof of concept (PoC) for the CVE-2026-58231 exploit. cybersecuritynews.com · securityaffairs.com
- [● 5 SOURCES] CVE-2026-58231 is a maximum-severity vulnerability in SAP Commerce Cloud with a CVSS score of 10.0. cybersecuritynews.com · www.kapitalmarktexperten.de · www.pcquest.com · securityaffairs.com · dev.to
- [● 5 SOURCES] The vulnerability allows unauthenticated remote code execution (RCE) via the Data Hub Adapter. cybersecuritynews.com · www.kapitalmarktexperten.de · www.pcquest.com · securityaffairs.com · dev.to
- [○ 1 SOURCE] Security firm Onapsis recommends that customers move to a fixed Commerce Cloud release to remediate the flaw. www.pcquest.com
- [● 4 SOURCES] Exploitation attempts against the SAP vulnerability were observed in honeypots three days after the official patch was released. cybersecuritynews.com · www.kapitalmarktexperten.de · securityaffairs.com · dev.to
- [○ 1 SOURCE] Initial attack traffic was traced to hosting infrastructure in the United States. cybersecuritynews.com