CVE Tools

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

The Hacker NewsBy The Hacker News

Reported exploitedSAP Commerce Cloud

Our summary

SAP Commerce Cloud is facing active exploitation attempts for CVE-2026-58231, a critical vulnerability rated 10.0 on the CVSS scale. The flaw allows unauthenticated attackers to bypass authorization checks and send invalid input to specific functions, potentially enabling arbitrary code execution and compromising internal components. Although no public proof-of-concept was previously available, threat intelligence firm Defused Cyber detected attacks beginning just three days after the patch was released. SAP advises customers to update to the fixed release levels or configure IP filters as a temporary mitigation.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store