SAP Commerce Cloud improper authorization RCE (CVE-2026-58231)
Vulnerability
Summary
Hide ▲
Show ▼
SAP Commerce Cloud CVE-2026-58231 is under active exploitation attempts after SAP released a fix for the flaw in the core Data Hub Adapter extension. The 10.0 CVSS vulnerability involves insufficient authorization checks and input validation and can let an unauthenticated attacker abuse a default authentication client to reach arbitrary code execution. Defused said exploitation attempts began hitting its honeypot systems three days after the patch was released, and Onapsis advised customers to patch to the fixed Commerce Cloud release levels and use an IP Filter Set as a temporary mitigation.
Related Happenings
SAP NetWeaver Application Server ABAP memory corruption memory corruption flaw (CVE-2026-44747)
Vulnerability
H score35
First: 14.07.2026 14:17
Last: 14.07.2026 14:17
Sources 1
About this happening:
SAP's July 2026 security patch day resolved CVE-2026-44747, a memory corruption bug in NetWeaver Application Server ABAP that could let attackers access and modi...
SAP NetWeaver Application Server ABAP memory corruption memory corruption flaw (CVE-2026-44747)
VulnerabilityAbout this happening: SAP's July 2026 security patch day resolved CVE-2026-44747, a memory corruption bug in NetWeaver Application Server ABAP that could let attackers access and modi...
SAP Commerce Cloud missing authentication check remote code execution flaw (CVE-2026-34263)
Vulnerability
H score34
First: 12.05.2026 14:04
Last: 12.05.2026 14:04
Sources 1
About this happening:
CVE-2026-34263 is a critical SAP Commerce Cloud flaw that can let unauthenticated attackers execute code on vulnerable servers. The weakness is a missing authenticat...
SAP Commerce Cloud missing authentication check remote code execution flaw (CVE-2026-34263)
VulnerabilityAbout this happening: CVE-2026-34263 is a critical SAP Commerce Cloud flaw that can let unauthenticated attackers execute code on vulnerable servers. The weakness is a missing authenticat...
Storm-1175 high-tempo Medusa ransomware campaign
Campaign
H score59
First: 07.04.2026 13:02
Last: 07.04.2026 13:02
Sources 1
About this happening:
Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
Storm-1175 high-tempo Medusa ransomware campaign
CampaignAbout this happening: Storm-1175 is running a high-tempo Medusa ransomware campaign that has repeatedly exploited n-day and zero-day flaws to gain initial access before patching closes the...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/Mitigation
H score46
First: 20.02.2026 19:02
Last: 20.02.2026 19:02
Sources 1
About this happening:
CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV mitigation for BeyondTrust CVE-2026-1731
Advisory/MitigationAbout this happening: CISA ordered urgent KEV mitigation for CVE-2026-1731 in BeyondTrust Remote Support and Privileged Remote Access, forcing affected federal deployments to apply th...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
14.08.2026 16:45 1 articles · 13d ago
SAP patches CVE-2026-58231 in Commerce Cloud
Mitigation Patch UpdateSAP released a fix for CVE-2026-58231 in SAP Commerce Cloud, closing an improper authorization weakness in the core Data Hub Adapter extension that allowed an unauthenticated attacker to submit specially crafted input and execute arbitrary code.
Show sources
- Max severity SAP Commerce Cloud flaw now targeted in attacks — www.bleepingcomputer.com — 14.08.2026 16:45
-
14.08.2026 16:45 3 articles · 13d ago
Defused sees CVE-2026-58231 exploitation attempts in honeypots
Exploitation ObservedDefused confirmed that CVE-2026-58231 was being targeted in the wild, with first exploitation attempts against SAP Commerce Cloud honeypots and no public proof-of-concept known at the time; SAP had not yet flagged the flaw as actively exploited in its advisory.
Show sources
- Max severity SAP Commerce Cloud flaw now targeted in attacks — www.bleepingcomputer.com — 14.08.2026 16:45
- Max severity SAP Commerce Cloud flaw now targeted in attacks — www.bleepingcomputer.com — 14.08.2026 16:45
- SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch — thehackernews.com — 15.08.2026 11:38