Critical SAP Commerce Cloud Vulnerability CVE-2026-58231 Exploited in the Wild
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is being actively exploited just three days after SAP released a security patch, according to threat intelligence firm Defused.
SAP Commerce Cloud, formerly known as SAP Hybris, is a cloud-based e-commerce platform used by online stores operated by major retailers and well-known global brands.
Tracked as CVE-2026-58231, the critical vulnerability has a CVSS score of 10.0 and is caused by improper authentication in the Commerce Cloud Core Data Hub Adapter extension. An unauthenticated, unprivileged attacker could exploit the flaw in a low-complexity attack to execute arbitrary code.
“SAP Commerce Cloud allows an unauthenticated attacker to abuse the default authentication client and submit specially crafted input to certain functions that have not been adequately validated,” SAP explains.
“Successful exploitation could lead to arbitrary code execution and compromise of internal components, potentially significantly impacting application confidentiality, integrity, and availability.”
SAP has not yet added CVE-2026-58231 to its list of vulnerabilities known to be actively exploited. However, security researchers at Defused said in a post on X that exploitation attempts were detected in the wild.

“The first exploitation attempt for CVE-2026-58231 (Unauthenticated RCE in SAP Commerce Cloud, CVSS 10.0) is reaching our honeypot three days after the patch date,” Defused said. “This vulnerability has no public PoC and is not known to have been exploited.”
When asked to confirm the Defused report, an SAP spokesperson told BleepingComputer that the company is aware of the issue and is investigating.
“The security note is publicly available to SAP customers and partners and was released on SAP’s August Patch Day. We encourage our customers and partners to patch their systems immediately,” the spokesperson added.
Internet security monitoring organization Shadowserver has identified more than 4,200 IP addresses with SAP Commerce Cloud fingerprints. Most of the exposed systems are located in Europe and North America.
However, it is unclear how many of these systems are honeypots or have already been secured against attacks targeting CVE-2026-58231.

In its July 2026 security update, SAP fixed 16 vulnerabilities. The company also addressed 30 additional flaws in its May and June updates, including three critical vulnerabilities affecting the Commerce Cloud e-commerce platform: CVE-2026-44761, CVE-2026-22732, and CVE-2026-34263.
In April, cybersecurity companies Aikido and Socket reported that attackers had compromised multiple official SAP npm packages in supply chain attacks designed to steal credentials from developers’ systems.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog. Three of those vulnerabilities have been exploited in ransomware attacks.
SAP is a German multinational software company that serves 99 of the world’s 100 largest companies. The company reported total revenue of more than 36 billion euros in 2025.
Updated Aug. 14 at 11:51 a.m. EDT: Added SAP statements.
The overall prevention score can hide what happens after the initial access. If an attacker uses valid credentials, your defenses drop sharply.
Blue Report 2026 measures defense techniques by technology across 338 million simulations run in customer production environments.
Source: www.bleepingcomputer.com




