Skip to content
Tech News
← Back to articles

Max severity SAP Commerce Cloud flaw now targeted in attacks

read original more articles
Why This Matters

The rapid targeting of the critical SAP Commerce Cloud vulnerability highlights the urgency for organizations to prioritize timely patching and security updates. As high-profile platforms used by major brands are now under attack, this underscores the increasing sophistication and prevalence of supply chain and e-commerce-related cyber threats, emphasizing the need for robust security measures in the tech industry and for consumers relying on these platforms.

Key Takeaways

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.

Commerce Cloud (formerly known as SAP Hybris) is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers.

Tracked as CVE-2026-58231, this critical flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud that threat actors without privileges can exploit in low-complexity attacks to execute arbitrary code.

"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," SAP explains.

"Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application."

While SAP has yet to flag this security flaw as actively exploited in a security advisory issued this Tuesday, Defused security researchers confirmed earlier today that CVE-2026-58231 is now being targeted in the wild.

CVE-2026-58231 exploitation attempt (Defused)

​"First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day," Defused warned in a Friday tweet. "This vulnerability has no public PoC and is not known to be exploited."

Internet security watchdog group Shadowserver tracks over 4,200 IP addresses with a SAP Commerce Cloud fingerprint, most of them from Europe and North America.

However, there is no information on how many of them are honeypots or have already been secured against CVE-2026-58231 attacks.

... continue reading