Max severity SAP Commerce Cloud flaw now targeted in attacks
Reported exploitedSAP Commerce CloudOur summary
Threat intelligence firm Defused reports that a critical remote code execution vulnerability in SAP Commerce Cloud is being actively targeted despite having only recently been patched. Tracked as CVE-2026-58231 with a maximum CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code by abusing a default authentication client within the Data Hub Adapter extension. Although SAP has not yet updated its official advisory to confirm widespread exploitation, shadow server data indicates over 4,200 internet-exposed instances remain vulnerable across Europe and North America. Organizations should apply the latest security fixes immediately to mitigate the risk of system compromise.
BleepingComputer publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.