Monitor this situation.
Unsubscribe anytime.
[SITUATION] · [ACTIVE] · [TECHNOLOGY]
2 clusters · 9 sources · 3 days · First seen · Last updated
SAP Commerce Cloud critical vulnerability
Overview
SAP identified and released patches for a critical vulnerability in its Commerce Cloud platform, designated as CVE-2026-58231. The flaw, which received a CVSS score of 10.0, resides in the Data Hub Adapter. Due to insufficient authorization checks and inadequate input validation, unauthenticated attackers could potentially execute arbitrary code, leading to full control over the commerce platform.
Following the release of the security updates, researchers observed active exploitation attempts via honeypots. These attacks involve abusing the default authentication client and input validation flaws to achieve remote code execution. While automated mass scanning has been detected, there is currently no public proof of concept, suggesting that attackers may have reverse-engineered the vendor patch. Initial attack traffic has been traced to hosting infrastructure in the United States.
Security researchers at Defused Cyber reported observing the first wave of exploitation attempts just three days after SAP released official security patches. Successful exploitation could grant attackers full administrative control over backend databases, transaction pipelines, and sensitive enterprise assets, impacting the confidentiality, integrity, and availability of global digital storefronts and supply chain operations.
In response to the active targeting, security firm Onapsis recommends that affected organizations immediately migrate to a fixed Commerce Cloud release. For those unable to patch immediately, implementing an IP Filter Set to restrict access to the vulnerable endpoint is suggested as a temporary mitigation.
Entities
SAP · Onapsis · Charlotte Colocation Center · Shadowserver · Defused Cyber
Claims
What the coverage asserts, and how well corroborated each claim is across sources.
- [● 5 SOURCES] CVE-2026-58231 is a maximum-severity vulnerability in SAP Commerce Cloud with a CVSS score of 10.0. cybersecuritynews.com · www.kapitalmarktexperten.de · www.pcquest.com · securityaffairs.com · dev.to
- [● 5 SOURCES] The vulnerability allows unauthenticated remote code execution (RCE) via the Data Hub Adapter. cybersecuritynews.com · www.kapitalmarktexperten.de · www.pcquest.com · securityaffairs.com · dev.to
- [● 4 SOURCES] Exploitation attempts against the SAP vulnerability were observed in honeypots three days after the official patch was released. cybersecuritynews.com · www.kapitalmarktexperten.de · securityaffairs.com · dev.to
- [● 2 SOURCES] There is currently no public proof of concept (PoC) for the CVE-2026-58231 exploit. cybersecuritynews.com · securityaffairs.com
- [○ 1 SOURCE] Security firm Onapsis recommends that customers move to a fixed Commerce Cloud release to remediate the flaw. www.pcquest.com
- [○ 1 SOURCE] Initial attack traffic was traced to hosting infrastructure in the United States. cybersecuritynews.com
Timeline
-
2 days ago
[TECHNOLOGY] 7 sourcesSAP Commerce Cloud vulnerability under active exploitationAttackers are actively exploiting a critical CVSS 10.0 vulnerability (CVE-2026-58231) in SAP Commerce Cloud, enabling unauthenticated remote code execution just days after a patch was released.
-
5 days ago
[TECHNOLOGY] 4 sourcesSAP patches critical 10.0 severity vulnerability in Commerce CloudSAP has patched a critical CVE-2026-58231 vulnerability in Commerce Cloud with a CVSS score of 10.0, which allows unauthenticated attackers to execute arbitrary code via the Data Hub Adapter.
Sources
borncity.com · dev.to · drweb.de · infoguerra.com.br · invitehealth.substack.com · it-boltwise.de · kapitalmarktexperten.de · pcquest.com · securityaffairs.co
This summary has been updated 1 time: see revision history