SAP Commerce Cloud improper authorization RCE (CVE-2026-58231)
Vulnerability
Summary
Hide ▲
Show ▼
SAP Commerce Cloud CVE-2026-58231 is being targeted three days after patching, exposing affected deployments to unauthenticated arbitrary code execution. The flaw sits in the core Data Hub Adapter extension and can be abused through low-complexity attacks. SAP has not yet flagged it as actively exploited, but defenders lack a public PoC and are already seeing attack attempts in the wild.
Related Happenings
SAP NetWeaver Application Server ABAP memory corruption memory corruption flaw (CVE-2026-44747)
Vulnerability
H score35
First: 14.07.2026 14:17
Last: 14.07.2026 14:17
Sources 1
About this happening:
SAP's July 2026 security patch day resolved CVE-2026-44747, a memory corruption bug in NetWeaver Application Server ABAP that could let attackers access and modi...
SAP NetWeaver Application Server ABAP memory corruption memory corruption flaw (CVE-2026-44747)
VulnerabilityAbout this happening: SAP's July 2026 security patch day resolved CVE-2026-44747, a memory corruption bug in NetWeaver Application Server ABAP that could let attackers access and modi...
SAP Commerce Cloud missing authentication check remote code execution flaw (CVE-2026-34263)
Vulnerability
H score34
First: 12.05.2026 14:04
Last: 12.05.2026 14:04
Sources 1
About this happening:
CVE-2026-34263 is a critical SAP Commerce Cloud flaw that can let unauthenticated attackers execute code on vulnerable servers. The weakness is a missing authenticat...
SAP Commerce Cloud missing authentication check remote code execution flaw (CVE-2026-34263)
VulnerabilityAbout this happening: CVE-2026-34263 is a critical SAP Commerce Cloud flaw that can let unauthenticated attackers execute code on vulnerable servers. The weakness is a missing authenticat...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector Action
H score53
First: 04.02.2026 07:50
Last: 04.02.2026 07:50
Sources 1
About this happening:
CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
CISA KEV remediation deadline for SolarWinds WHD CVE-2025-40551
Public Sector ActionAbout this happening: CISA added CVE-2025-40551 in SolarWinds Web Help Desk to the KEV catalog and imposed federal remediation deadlines, turning a newly exploited flaw into a compl...
Timeline
-
14.08.2026 16:45 1 articles · 2h ago
SAP patches CVE-2026-58231 in Commerce Cloud
Mitigation Patch UpdateSAP released a fix for CVE-2026-58231 in SAP Commerce Cloud, closing an improper authorization weakness in the core Data Hub Adapter extension that allowed an unauthenticated attacker to submit specially crafted input and execute arbitrary code.
Show sources
- Max severity SAP Commerce Cloud flaw now targeted in attacks — www.bleepingcomputer.com — 14.08.2026 16:45
-
14.08.2026 16:45 2 articles · 2h ago
Defused sees CVE-2026-58231 exploitation attempts in honeypots
Exploitation ObservedDefused confirmed that CVE-2026-58231 was being targeted in the wild, with first exploitation attempts against SAP Commerce Cloud honeypots and no public proof-of-concept known at the time; SAP had not yet flagged the flaw as actively exploited in its advisory.
Show sources
- Max severity SAP Commerce Cloud flaw now targeted in attacks — www.bleepingcomputer.com — 14.08.2026 16:45
- Max severity SAP Commerce Cloud flaw now targeted in attacks — www.bleepingcomputer.com — 14.08.2026 16:45