Defused confirms SAP Commerce Cloud flaw under attack three days after patch
This digest was compiled by AI from multiple sources — links to the originals are below.

Threat intelligence company Defused confirmed Friday that attackers are targeting a maximum-severity remote code execution vulnerability in SAP Commerce Cloud patched three days ago. The flaw, CVE-2026-58231, allows unauthenticated attackers to execute arbitrary code, and SAP has not yet flagged it as actively exploited in its Tuesday advisory. Shadowserver tracks more than 4,200 IP addresses with a Commerce Cloud fingerprint, mostly in Europe and North America, though how many remain unpatched is unknown.
The Vulnerability
CVE-2026-58231 is a critical improper authorization weakness in the core Data Hub Adapter extension of SAP Commerce Cloud, formerly SAP Hybris. SAP rates it CVSS 10.0 and says an unauthenticated attacker can abuse a default authentication client to submit crafted input to functions lacking sufficient validation. Successful exploitation enables arbitrary code execution and compromises internal components, with high impact on confidentiality, integrity, and availability. SAP patched the flaw three days ago.
Active Exploitation
Defused said Friday that first exploitation attempts against CVE-2026-58231 hit its honeypots three days after patch day. The company warned that the vulnerability has no public proof-of-concept and was not previously known to be exploited. SAP has not flagged the flaw as actively exploited in its security advisory issued Tuesday.
Exposure and Recent SAP Patching
Shadowserver tracks more than 4,200 IP addresses with a SAP Commerce Cloud fingerprint, most in Europe and North America. It is unclear how many are honeypots or have applied the patch. SAP fixed 16 vulnerabilities in its July 2026 Security Patch package and 30 more in June and May, including three critical Commerce Cloud flaws tracked as CVE-2026-44761, CVE-2026-22732, and CVE-2026-34263. In April, Aikido and Socket reported compromised SAP npm packages in a supply chain attack aimed at stealing developer credentials. Since November 2021, CISA has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog, including three used in ransomware attacks.
What's Next
SAP may update its advisory in the coming days as exploitation attempts continue. It remains unclear how many of the 4,200 exposed Commerce Cloud instances remain unpatched or whether attacks will escalate beyond honeypot probes.
1 source
Defused confirms SAP Commerce Cloud flaw under attack three days after patch



