Critical SAP Commerce Cloud RCE Actively Exploited Just Days After Patch
A maximum-severity remote code execution vulnerability in **SAP Commerce Cloud**, patched just three days ago, is already under active attack. Identified as **CVE-2026-58231**, this critical flaw allows unauthenticated attackers to execute arbitrary code, posing a significant risk to the high-profile global brands and large retailers utilizing the e-commerce platform.
Threat actors are actively targeting a critical remote code execution (RCE) vulnerability in **SAP Commerce Cloud** (formerly **SAP Hybris**), mere days after **SAP** released a patch. The flaw, tracked as **CVE-2026-58231**, carries a maximum severity rating and allows unauthenticated attackers to execute arbitrary code with low attack complexity.

### The Vulnerability: CVE-2026-58231
**CVE-2026-58231** stems from an improper authorization weakness within the core **Data Hub Adapter** extension for **Commerce Cloud**. This allows threat actors to exploit a default authentication client by submitting specially crafted input to functions lacking sufficient validation.
**SAP**'s explanation highlights the severity: "Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application."
### In-the-Wild Exploitation Confirmed
While **SAP** had not officially flagged **CVE-2026-58231** as actively exploited in its August 2026 security advisory, threat intelligence company **Defused** confirmed earlier today that exploitation attempts are now hitting their honeypots.

**Defused** noted on Friday: "First exploitation attempts against **CVE-2026-58231** (unauth RCE in **SAP Commerce Cloud**, CVSS 10.0) is now hitting our honeypots - 3 days after patch day." They also pointed out that, at the time, no public Proof-of-Concept (PoC) for the vulnerability was known.
**SAP** has acknowledged and is investigating the reports, urging customers to apply the patch immediately. A security note, **3771065**, has been published and is available for **SAP** customers and partners.
### Widespread Exposure and Ongoing Risks
The internet security watchdog group **Shadowserver** tracks over 4,200 IP addresses with an **SAP Commerce Cloud** fingerprint, primarily located in Europe and North America. The actual number of vulnerable instances remains unclear, as does the extent of successful exploitation.

This incident is the latest in a series of critical vulnerabilities affecting **SAP** products. In recent months, **SAP** has addressed numerous flaws, including several critical issues in **Commerce Cloud** and **NetWeaver**. The **U.S. Cybersecurity and Infrastructure Security Agency (CISA)** has added 14 **SAP** vulnerabilities to its **Known Exploited Vulnerabilities** catalog since November 2021, with three of these having been abused in ransomware attacks.
**SAP**, a German multinational software corporation, serves 99 of the 100 largest companies worldwide, underscoring the potential impact of such vulnerabilities.