Max severity SAP Commerce Cloud flaw now targeted in attacks

Max severity SAP Commerce Cloud flaw now targeted in attacks
Defused says attackers are already targeting CVE-2026-58231, a critical unauthenticated RCE flaw in SAP Commerce Cloud that was patched just three days earlier. The issue affects a widely used e-commerce platform for major global brands, and Shadowserver has identified over 4,200 exposed SAP Commerce Cloud IPs worldwide. #CVE-2026-58231 #SAPCommerceCloud #Defused #Shadowserver

Keypoints

  • CVE-2026-58231 is a critical SAP Commerce Cloud RCE vulnerability.
  • The flaw comes from improper authorization in the Data Hub Adapter extension.
  • Attackers can exploit it without privileges and execute arbitrary code.
  • Defused confirmed active exploitation attempts only three days after patching.
  • Shadowserver found more than 4,200 internet-exposed SAP Commerce Cloud IP addresses.

Read More: https://www.bleepingcomputer.com/news/security/max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/