Attackers Exploit Critical SAP Commerce Cloud Flaw Days After Patch
A maximum-severity RCE vulnerability in SAP Commerce Cloud is seeing active exploitation just 72 hours after a fix was released.
Attackers are actively exploiting a critical remote code execution (RCE) vulnerability in SAP Commerce Cloud, striking just three days after a security patch became available. The flaw allows unauthenticated actors to take full control of affected systems, posing an immediate threat to global enterprises using the platform.
Identified as CVE-2026-58231, the vulnerability specifically impacts the SAP Commerce Cloud Data Hub Adapter. According to reports from The Hacker News and Lumi AI News, the flaw has been assigned a CVSS score of 10.0, the maximum possible rating for severity. The technical mechanism involves an unauthenticated attacker abusing a default authentication client to submit specially crafted input to functions that lack sufficient validation, resulting in arbitrary code execution. Threat intelligence firm Defused first detected the active exploitation attempts shortly after the patch was made public.
The Enterprise Risk
SAP Commerce Cloud serves as a large-scale e-commerce engine for global corporations, managing critical business data and trade operations. Because the platform handles sensitive customer information and financial transactions, an RCE vulnerability of this magnitude is particularly dangerous. A successful breach can lead to total system compromise, the theft of proprietary data, and the complete disruption of commercial operations.
The Speed of Exploitation
The rapid transition from patch release to active targeting—a window of only 72 hours—underscores a growing trend in modern cyber warfare. Threat actors frequently reverse-engineer official security updates to identify the exact location of a vulnerability, effectively using the patch as a roadmap for their attacks. This "race to patch" puts organizations at extreme risk if their update cycles are slower than the attackers' ability to weaponize the flaw.
Immediate Outlook
Given the unauthenticated nature of the exploit and its perfect CVSS score, any unpatched instance of the SAP Commerce Cloud Data Hub Adapter is considered at extreme risk of immediate compromise. Security teams are urged to prioritize the deployment of the available patch to close the window of opportunity for attackers. While the initial exploitation attempts have been flagged by Defused, the full scale of the impact across the enterprise landscape remains to be determined.