Defused says attackers are already targeting CVE-2026-58231, a critical unauthenticated RCE flaw in SAP Commerce Cloud that was patched just three days earlier. The issue affects a widely used e-commerce platform for major global brands, and Shadowserver has identified over 4,200 exposed SAP Commerce Cloud IPs worldwide. #CVE-2026-58231 #SAPCommerceCloud #Defused #Shadowserver
Keypoints
- CVE-2026-58231 is a critical SAP Commerce Cloud RCE vulnerability.
- The flaw comes from improper authorization in the Data Hub Adapter extension.
- Attackers can exploit it without privileges and execute arbitrary code.
- Defused confirmed active exploitation attempts only three days after patching.
- Shadowserver found more than 4,200 internet-exposed SAP Commerce Cloud IP addresses.