Maximum-severity SAP Commerce Cloud vulnerability (CVE-2026-58231) now under active exploitation
A CVSS 10.0 flaw in SAP $SAP Commerce Cloud's Data Hub Adapter is being actively targeted just days after SAP's August patch, per The Hacker News and BleepingComputer.
SAP $SAP Commerce Cloud is facing active exploitation of a maximum-severity flaw, CVE-2026-58231, rated 10.0 on the CVSS scale. The bug stems from an authorization weakness in the platform's Data Hub Adapter extension that lets an unauthenticated attacker abuse a default authentication client to run arbitrary code. Threat intelligence firm Defused said exploitation attempts began hitting its honeypots three days after SAP released a fix on its August Patch Tuesday. Shadowserver has tracked over 4,200 internet-exposed SAP Commerce Cloud instances, mostly in Europe and North America. SAP confirmed it is investigating; no attacker has been identified. Sources: The Hacker News, BleepingComputer.