Find notable cyber news and cases, enriched with sources, timelines, and signals.

SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 patch release

Security Patch Release
First reported
Last updated
Happening score
H score 44
1 unique sources, 2 articles

Summary

Hide ▲

SAP Commerce Cloud (Data Hub Adapter) CVE-2026-58231 is a maximum-severity CVSS 10.0 vulnerability that can let an unauthenticated attacker abuse a default authentication client and submit crafted input to vulnerable functions. The flaw stems from insufficient authorization checks and input validation and can lead to arbitrary code execution and compromise of internal components. SAP released patches and Onapsis told customers to move to a fixed release, re-build/re-deploy the updated version, and use an IP Filter Set as a temporary mitigation. Defused Cyber said exploitation attempts began reaching its honeypot systems three days after the patch was released.

Related Happenings

SAP security patch release for CVE-2026-44747

Security Patch Release
H score40 First: 14.07.2026 21:17 Last: 14.07.2026 21:17 Sources 1

About this happening: SAP's July 2026 security updates now cover multiple vulnerabilities, including a critical SAP NetWeaver Application Server ABAP flaw. The bundle includes CVE-2026-44...

SAP July 2026 security updates

Security Patch Release
H score31 First: 14.07.2026 14:42 Last: 14.07.2026 14:42 Sources 1

About this happening: SAP's July 2026 security updates address 16 vulnerabilities across NetWeaver, Commerce Cloud, and AppRouter, including three critical flaws. The release closes a *...

SAP July 2026 security patch day

Security Patch Release
H score40 First: 14.07.2026 14:17 Last: 14.07.2026 14:17 Sources 1

About this happening: SAP released 19 new and updated security notes for its July 2026 security patch day, covering NetWeaver, Approuter, Commerce Cloud, and other products with...

Fortinet security patch release for CVE-2026-25089

Security Patch Release
H score44 First: 10.06.2026 18:10 Last: 10.06.2026 18:10 Sources 1

About this happening: Fortinet, Ivanti, and SAP released security updates that address multiple critical vulnerabilities across FortiSandbox, Ivanti Sentry, and SAP prod...

Latest development: 11.06.2026 09:20

Shadowserver reported large-scale exploitation attempts against Internet-exposed Ivanti Sentry gateways after CVE-2026-10520 was patched in R10.5.2, R10.6.2, and R10.7.1, saying it saw 19 vulnerable instances and at least 2 backdoored systems and warning that unpatched devices were most likely compromised.

SAP June 2026 Security Patch package for NetWeaver and Commerce Cloud

Security Patch Release
H score24 First: 09.06.2026 22:36 Last: 09.06.2026 22:36 Sources 1

About this happening: SAP released fixes for 15 vulnerabilities in its June 2026 Security Patch package, including four critical flaws in SAP NetWeaver and SAP Commerce Cloud th...

Timeline

  1. 12.08.2026 10:31 3 articles · 13d ago

    SAP releases patches for CVE-2026-58231 in Commerce Cloud (Data Hub Adapter)

    Initial Disclosure

    SAP released patches for CVE-2026-58231, a maximum-severity 10.0 flaw in Commerce Cloud (Data Hub Adapter) that allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to functions with insufficient validation, potentially leading to arbitrary code execution and compromise of internal components. Onapsis advised customers to patch to a fixed Commerce Cloud release, re-deploy the updated version, and temporarily restrict access to the vulnerable endpoint with an IP Filter Set.

    Show sources