Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
Reported exploitedSAP Commerce CloudOur summary
Threat intelligence firms have confirmed active exploitation of CVE-2026-58231, a critical vulnerability in SAP Commerce Cloud, beginning just three days after the patch release on August 11. This flaw involves inadequate authorization checks and input validation, enabling attackers to execute arbitrary code and compromise internal systems with a perfect CVSS score of 10. While CISA has not yet added this specific ID to its Known Exploited Vulnerabilities catalog, independent sensors have detected attack attempts since August 14.
SecurityWeek publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.