Find notable cyber news and cases, enriched with sources, timelines, and signals.

SAP Commerce Cloud improper authorization RCE (CVE-2026-58231)

Vulnerability
First reported
Last updated
Happening score
H score 49
1 unique sources, 1 articles

Summary

Hide ▲

SAP Commerce Cloud CVE-2026-58231 is being targeted three days after patching, exposing affected deployments to unauthenticated arbitrary code execution. The flaw sits in the core Data Hub Adapter extension and can be abused through low-complexity attacks. SAP has not yet flagged it as actively exploited, but defenders lack a public PoC and are already seeing attack attempts in the wild.

Related Happenings

SAP NetWeaver Application Server ABAP memory corruption memory corruption flaw (CVE-2026-44747)

Vulnerability
H score35 First: 14.07.2026 14:17 Last: 14.07.2026 14:17 Sources 1

About this happening: SAP's July 2026 security patch day resolved CVE-2026-44747, a memory corruption bug in NetWeaver Application Server ABAP that could let attackers access and modi...

SAP Commerce Cloud missing authentication check remote code execution flaw (CVE-2026-34263)

Vulnerability
H score34 First: 12.05.2026 14:04 Last: 12.05.2026 14:04 Sources 1

About this happening: CVE-2026-34263 is a critical SAP Commerce Cloud flaw that can let unauthenticated attackers execute code on vulnerable servers. The weakness is a missing authenticat...

CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551

Public Sector Action
H score53 First: 04.02.2026 07:50 Last: 04.02.2026 07:50 Sources 1

About this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...

Timeline

  1. 14.08.2026 16:45 1 articles · 2h ago

    SAP patches CVE-2026-58231 in Commerce Cloud

    Mitigation Patch Update

    SAP released a fix for CVE-2026-58231 in SAP Commerce Cloud, closing an improper authorization weakness in the core Data Hub Adapter extension that allowed an unauthenticated attacker to submit specially crafted input and execute arbitrary code.

    Show sources
  2. 14.08.2026 16:45 2 articles · 2h ago

    Defused sees CVE-2026-58231 exploitation attempts in honeypots

    Exploitation Observed

    Defused confirmed that CVE-2026-58231 was being targeted in the wild, with first exploitation attempts against SAP Commerce Cloud honeypots and no public proof-of-concept known at the time; SAP had not yet flagged the flaw as actively exploited in its advisory.

    Show sources