BTC$63,057+0.34% LTC$44.05+1.12% XMR$412.08+4.33%
TorPortal TorPortalMarkets, mirrors, dark web news
BleepingComputer · Aug 14, 2026 · 2 min read · Original story

Max severity SAP Commerce Cloud flaw now targeted in attacks

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.

Commerce Cloud (formerly known as SAP Hybris) is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers.

Tracked as CVE-2026-58231, this critical flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud that threat actors without privileges can exploit in low-complexity attacks to execute arbitrary code.

"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," SAP explains.

"Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application."

While SAP has yet to flag this security flaw as actively exploited in a security advisory issued this Tuesday, Defused security researchers confirmed earlier today that CVE-2026-58231 is now being targeted in the wild.

CVE-2026-58231 exploitation attempt (Defused)

​"First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day," Defused warned in a Friday tweet. "This vulnerability has no public PoC and is not known to be exploited."

A SAP spokesperson told BleepingComputer that the company is aware of and investigating this issue when asked to confirm Defused's report.

"A security note https://me.sap.com/notes/3771065 is published and available for SAP customers and partners and was released on SAP’s August Patch Day. We recommend customers and partners patch their systems with immediate effect," the spokesperson added.

Internet security watchdog group Shadowserver tracks over 4,200 IP addresses with a SAP Commerce Cloud fingerprint, most of them from Europe and North America.

However, there is no information on how many of them are honeypots or have already been secured against CVE-2026-58231 attacks.

Internet-exposed SAP Commerce Cloud instances (Shadowserver)

​Most recently, SAP fixed 16 vulnerabilities in its July 2026 Security Patch package and 30 more vulnerabilities in June and May, including three more critical security flaws (CVE-2026-44761, CVE-2026-22732, and CVE-2026-34263) affecting the Commerce Cloud enterprise-grade e-commerce platform.

In April, cybersecurity companies Aikido and Socket also reported that attackers aiming to steal credentials from developers' systems compromised multiple official SAP npm packages in a supply chain attack.

Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog, including three that were abused in ransomware attacks.

SAP is a German multinational software corporation that serves 99 of the 100 largest companies worldwide and has reported total revenues exceeding €36 billion in fiscal year 2025.

Update August 14, 11:51 EDT: Added SAP statement.

References in this story

  1. NVD - CVE-2026-58231 nvd.nist.gov
  2. AI Threat Readiness Playbook for Cloud Security Teams | Wiz wiz.io Prepare for AI-driven threats. Discover best practices for exposure management, AI-powered code analysis, and real-time threat detection.
  3. SAP Security Patch Day - August 2026 support.sap.com SAP security Patch Day Bulletin
  4. Defused (@DefusedCyber) on X x.com 🚨 First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day. This vulnerability has no public PoC and is not known to be…
  5. me.sap.com
  6. Time series · IoT device statistics · The Shadowserver Foundation dashboard.shadowserver.org
  7. SAP warns of critical flaws in NetWeaver and Commerce Cloud www.bleepingcomputer.com SAP has addressed 16 vulnerabilities across multiple products as part of its July 2026 security updates, including three critical flaws in NetWeaver, Commerce Cloud, and AppRouter.
  8. SAP fixes critical flaws in NetWeaver and Commerce Cloud www.bleepingcomputer.com SAP has released fixes for 15 vulnerabilities as part of its June 2026 Security Patch package, including four critical-severity flaws affecting SAP NetWeaver and SAP Commerce Cloud.
  9. SAP fixes critical vulnerabilities in Commerce Cloud and S/4HANA www.bleepingcomputer.com SAP has released the May 2026 security updates addressing 15 vulnerabilities across multiple products, including two critical flaws in the Commerce Cloud enterprise-grade e-commerce platform and the S/4HANA ERP suite.
  10. NVD - CVE-2026-44761 nvd.nist.gov
  11. NVD - CVE-2026-22732 nvd.nist.gov
  12. NVD - CVE-2026-34263 nvd.nist.gov
  13. Official SAP npm packages compromised to steal credentials www.bleepingcomputer.com Multiple official SAP npm packages were compromised in what is believed to be a TeamPCP supply-chain attack to steal credentials and authentication tokens from developers' systems.
  14. Known Exploited Vulnerabilities Catalog | CISA www.cisa.gov For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat activity—CISA maintains the authoritative source of…

← Back to all news