SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
Reported exploitedSAP Commerce CloudOur summary
SAP Commerce Cloud is facing active exploitation attempts for CVE-2026-58231, a critical vulnerability rated 10.0 on the CVSS scale. The flaw allows unauthenticated attackers to bypass authorization checks and send invalid input to specific functions, potentially enabling arbitrary code execution and compromising internal components. Although no public proof-of-concept was previously available, threat intelligence firm Defused Cyber detected attacks beginning just three days after the patch was released. SAP advises customers to update to the fixed release levels or configure IP filters as a temporary mitigation.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.