Maximum-severity SAP Commerce Cloud flaw already under attack, three days after patch
A CVSS 10.0 unauthenticated remote code execution flaw in SAP Commerce Cloud's Data Hub Adapter is being targeted in the wild just three days after SAP patched it, per The Hacker News and BleepingComputer.
SAP Commerce Cloud, an e-commerce platform used by major global retailers, has a maximum-severity vulnerability (CVE-2026-58231, CVSS 10.0) in its Data Hub Adapter extension that lets unauthenticated attackers execute arbitrary code. SAP patched the flaw on its August 11, 2026 Security Patch Day. Threat intelligence firm Defused reported the first exploitation attempts hit its honeypots on August 14, just three days later. There is no public proof-of-concept and no confirmed identity behind the attempts. Shadowserver counts more than 4,200 internet-exposed SAP Commerce Cloud instances, mostly in Europe and North America. SAP confirmed to BleepingComputer it is aware of and investigating the activity. Sources: The Hacker News, BleepingComputer.