< Back to situations

Monitor this situation.

[SITUATION] · [ACTIVE] · [TECHNOLOGY]

2 clusters · 9 sources · 3 days · First seen · Last updated

SAP Commerce Cloud critical vulnerability

Overview

SAP identified and released patches for a critical vulnerability in its Commerce Cloud platform, designated as CVE-2026-58231. The flaw, which received a CVSS score of 10.0, resides in the Data Hub Adapter. Due to insufficient authorization checks and inadequate input validation, unauthenticated attackers could potentially execute arbitrary code, leading to full control over the commerce platform.

Following the release of the security updates, researchers observed active exploitation attempts via honeypots. These attacks involve abusing the default authentication client and input validation flaws to achieve remote code execution. While automated mass scanning has been detected, there is currently no public proof of concept, suggesting that attackers may have reverse-engineered the vendor patch. Initial attack traffic has been traced to hosting infrastructure in the United States.

Security researchers at Defused Cyber reported observing the first wave of exploitation attempts just three days after SAP released official security patches. Successful exploitation could grant attackers full administrative control over backend databases, transaction pipelines, and sensitive enterprise assets, impacting the confidentiality, integrity, and availability of global digital storefronts and supply chain operations.

In response to the active targeting, security firm Onapsis recommends that affected organizations immediately migrate to a fixed Commerce Cloud release. For those unable to patch immediately, implementing an IP Filter Set to restrict access to the vulnerable endpoint is suggested as a temporary mitigation.

Entities

SAP · Onapsis · Charlotte Colocation Center · Shadowserver · Defused Cyber

Claims

What the coverage asserts, and how well corroborated each claim is across sources.

Timeline

  1. 2 days ago

    [TECHNOLOGY] 7 sources
    SAP Commerce Cloud vulnerability under active exploitation

    Attackers are actively exploiting a critical CVSS 10.0 vulnerability (CVE-2026-58231) in SAP Commerce Cloud, enabling unauthenticated remote code execution just days after a patch was released.

  2. 5 days ago

    [TECHNOLOGY] 4 sources
    SAP patches critical 10.0 severity vulnerability in Commerce Cloud

    SAP has patched a critical CVE-2026-58231 vulnerability in Commerce Cloud with a CVSS score of 10.0, which allows unauthenticated attackers to execute arbitrary code via the Data Hub Adapter.

Sources

borncity.com · dev.to · drweb.de · infoguerra.com.br · invitehealth.substack.com · it-boltwise.de · kapitalmarktexperten.de · pcquest.com · securityaffairs.co

This summary has been updated 1 time: see revision history