SAP Commerce Cloud, an e-commerce platform used by large retailers and consumer brands to run their online stores, has a security flaw serious enough to earn the highest possible severity score, and attackers are already trying to exploit it.
The vulnerability, tracked as CVE-2026-58231, received a CVSS score of 10.0, the maximum on the scale used to rate how dangerous a security flaw is. SAP fixed the issue on August 11, 2026, as part of its regular monthly Patch Day. Three days later, on August 14, the threat intelligence firm Defused said it had detected active exploitation attempts through its network of honeypots, decoy systems designed to lure and record attacker activity, and shared the finding publicly on social media.
The flaw sits in the Data Hub Adapter, a component of SAP Commerce Cloud (formerly known as SAP Hybris) that handles data integration for online stores. According to SAP’s own description of the bug, an attacker does not need to be logged in or authenticated at all. Instead, they can abuse a default authentication client built into the software and send specially crafted input to functions that fail to properly validate it. If successful, this lets the attacker run arbitrary code on the affected system, essentially handing them control over it.
What makes this case unusual is the short gap between patch and exploitation. Defused’s initial assessment, before it observed real attacks, was that no public proof-of-concept code existed and the flaw was not known to be exploited. That changed within days, which suggests attackers analyzed the difference between the patched and unpatched versions of the software, a technique commonly known as patch diffing, to work out how to exploit the underlying weakness themselves.
The security firm Shadowserver, which scans the internet for exposed systems, has counted more than 4,200 internet-facing SAP Commerce Cloud instances, with the largest concentrations in Europe and North America. Not every one of those systems is necessarily vulnerable or unpatched, but the number gives a sense of how much exposure exists for a widely deployed enterprise platform.
SAP security specialist Onapsis, which tracks threats against SAP products specifically, noted that the August update also fixed three other critical vulnerabilities in related SAP products and urged customers to apply all of them without delay. The firm pointed to a pattern of past SAP flaws being exploited by financially motivated ransomware groups, including BianLian and RansomExx, as well as by state-linked hacking groups researchers track under names such as UNC5221, UNC5174 and CL-STA-0048. There is no confirmation yet that any of those specific groups are behind the current SAP Commerce Cloud attacks.
SAP is telling customers to patch their systems immediately, pointing them to security note 3771065 for instructions on updating to a fixed release and redeploying it. For organizations that cannot patch right away, SAP suggests a temporary workaround: configuring an IP Filter Set to restrict access to the vulnerable endpoint until the update can be applied.
No specific victims or data losses tied to this vulnerability have been publicly confirmed as of this writing, and no organization has issued a breach disclosure linked to this CVE.
Source: The Hacker News, “SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch”, with additional reporting from BleepingComputer.
