V-Help
← All news
Security

Critical SAP Commerce Cloud Vulnerability Already Exploited by Hackers

Critical SAP Commerce Cloud Vulnerability Already Exploited by Hackers

Photo: BleepingComputer

Quick answer

Hackers have begun exploiting the critical CVE-2026-58231 vulnerability in SAP Commerce Cloud, enabling unauthenticated remote code execution.

Cybersecurity experts from Defused have detected the first exploitation attempts of a critical vulnerability in SAP Commerce Cloud (CVE-2026-58231) just three days after the patch was released. The vulnerability, rated 10 on the CVSS scale, allows attackers to execute arbitrary code on vulnerable systems without authentication.

The issue affects the Data Hub Adapter extension within SAP Commerce Cloud—a cloud-based e-commerce platform used by major retailers and global brands. Due to insufficient data validation, attackers can bypass authentication mechanisms and gain control over internal system components, threatening the application’s confidentiality, integrity, and availability.

While SAP has not yet confirmed exploitation in its official bulletin, company representatives stated they are aware of the situation and conducting an investigation. SAP emphasized that the patch was released on August 13 as part of its routine security update and strongly urged customers to update their systems immediately.

According to monitoring group Shadowserver, over 4,200 IP addresses exhibiting SAP Commerce Cloud signatures are present online, primarily located in Europe and North America. However, it remains unclear how many of these systems are already patched or serve as honeypots for tracking cyber threats.

Earlier this year, SAP addressed other critical vulnerabilities in Commerce Cloud, including three severe issues in May and June. In April, supply chain attacks were also detected, where threat actors compromised several official SAP packages in the npm repository to steal developer credentials.

Common questions

What is CVE-2026-58231?
CVE-2026-58231 is a critical vulnerability in SAP Commerce Cloud that allows attackers to execute arbitrary code remotely without authentication. The flaw stems from insufficient data validation in the Data Hub Adapter extension.
Who is at risk?
All organizations using unpatched SAP Commerce Cloud are at risk. The platform is widely adopted by major retailers and global brands for e-commerce operations.
How can organizations protect themselves?
SAP released a patch as part of its August security updates. Organizations must apply the patch immediately to mitigate the risk of exploitation.
Share:

Dzen feed: /feed/dzen.xml · RSS: /feed.xml

Why trust this

Prepared by the V-Help editorial team from the primary source with a published date.

Published by: V-Help.ru news desk

Source: BleepingComputer