Security researchers have detected attacks targeting a maximum-severity SAP Commerce Cloud vulnerability only three days after SAP released a fix.
The SAP Commerce Cloud flaw, tracked as CVE-2026-58231, allows an unauthenticated attacker to execute arbitrary code. Defused researchers first spotted exploitation attempts against their honeypots on Friday.
Critical flaw enables remote code execution
CVE-2026-58231 affects the core Data Hub Adapter extension in SAP Commerce Cloud, previously known as SAP Hybris.
SAP assigned the vulnerability a CVSS score of 10.0, the highest possible severity rating. The issue stems from improper authorisation and requires neither valid credentials nor complex attack steps.
According to SAP, an attacker can abuse a default authentication client and send specially crafted input to vulnerable functions that lack adequate validation.
Successful exploitation could give an attacker the ability to run arbitrary code and compromise internal application components. That could affect the confidentiality, integrity and availability of an affected system.
Researchers detect attacks in the wild
SAP did not list the SAP Commerce Cloud flaw as actively exploited when it released its August security advisory. However, threat intelligence company Defused said it detected exploitation attempts shortly afterwards.
Defused reported that the attacks reached its honeypots just three days after SAP’s Patch Day. The researchers noted that no public proof-of-concept exploit was available and that they had not previously seen the flaw exploited.
SAP confirmed it is aware of the report and is investigating the activity.
The company urged customers and partners to apply the available security update immediately.
Thousands of exposed systems may face risk
Shadowserver tracks more than 4,200 IP addresses that appear to run SAP Commerce Cloud. Most of the identified systems are located in Europe and North America.
However, the number does not reveal how many instances are honeypots, already patched or exposed to the internet in a way that attackers can reach.
SAP Commerce Cloud is a cloud-based e-commerce platform used by large retailers and international brands. It can hold valuable customer, product and business data, making unpatched installations an attractive target.
SAP continues to patch high-impact issues
SAP has issued several security updates for Commerce Cloud in recent months.
Its July 2026 Security Patch package fixed 16 vulnerabilities, while SAP addressed 30 more flaws across May and June. Those updates included three additional critical Commerce Cloud issues: CVE-2026-44761, CVE-2026-22732 and CVE-2026-34263.
The company also faced a supply-chain incident earlier this year. In April, Aikido and Socket reported that attackers had compromised multiple official SAP npm packages in an effort to steal developer credentials.
CISA has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog since November 2021. Three of those flaws were used in ransomware attacks, underlining why organisations should treat the latest SAP Commerce Cloud flaw as an urgent patching priority.


0 responses to “SAP Commerce Cloud Flaw Targeted in Attacks”