Security researchers have detected attacks targeting a maximum-severity SAP Commerce Cloud vulnerability only three days after SAP released a fix. The SAP Commerce Cloud flaw, tracked as CVE-2026-58231, allows an unauthenticated attacker to execute arbitrary code. Defused researchers first spotted exploitation attempts against their honeypots on Friday. Critical flaw enables remote code execution CVE-2026-58231 affects…
SAP security updates released for July 2026 fix 16 vulnerabilities across several enterprise products. The update includes three critical flaws affecting NetWeaver, Commerce Cloud, and AppRouter, along with multiple high-severity security issues. Although SAP has not seen any active attacks targeting these vulnerabilities, organizations are encouraged to install the updates as soon as possible. Critical…
A SAP npm packages compromise exposed sensitive developer data through a supply chain attack. Attackers inserted malicious code into official packages and triggered credential theft during installation. Official Packages Turned Into Attack Vectors The attack targeted trusted SAP npm packages distributed through the npm registry. These tools are widely used in development workflows, which increased…