Skip to main content
Emerging ThreatsMalware & Ransomware

SAP Commerce Cloud Vulnerability Now Under Active Attack

Retail store checkout counter with point-of-sale terminal and shopping cart.

"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," SAP explains.

CVE-2026-58231 and the Data Hub Adapter

Three days after SAP issued a patch, security researchers reported that a maximum-severity remote code execution vulnerability in SAP Commerce Cloud is already being targeted. Tracked as CVE-2026-58231, the flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud (formerly SAP Hybris). According to SAP's advisory language quoted above, an unauthenticated actor can abuse a default authentication client and submit specially crafted input to functions lacking sufficient validation; successful exploitation can enable arbitrary code execution and compromise internal components, with high impact on confidentiality, integrity, and availability.

Defused detection and early exploitation signals

Defused, a threat intelligence company, reported on Friday that exploitation attempts are appearing in the wild. In a tweet the firm said, "First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day." Defused also noted the vulnerability had no public proof-of-concept at the time of their detection and was not previously known to be exploited publicly.

SAP itself, in a security advisory issued Tuesday, had not labeled the flaw as actively exploited when that advisory published. The near-immediate targeting observed by Defused underscores the short window between patch availability and attack activity in this instance.

Shadowserver footprint: 4,200+ IPs with Commerce Cloud fingerprints

Internet security watchdog Shadowserver reports more than 4,200 IP addresses with a SAP Commerce Cloud fingerprint, with most of those addresses located in Europe and North America. The Shadowserver tally does not, however, distinguish between honeypots and live, potentially vulnerable installations; there is no public information in the advisory on how many of the tracked endpoints are already secured against CVE-2026-58231 or are being monitored as traps for attackers.

Commerce Cloud is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers. That footprint — large deployments in multiple regions — is a factor in the rapid interest from attackers once a critical flaw and patch became public.

Recent SAP fixes and the April npm supply-chain incident

This vulnerability arrives against the backdrop of a busy patch cadence from SAP. The vendor fixed 16 vulnerabilities in its July 2026 Security Patch package and addressed 30 additional vulnerabilities in June and May, including three other critical Commerce Cloud flaws: CVE-2026-44761, CVE-2026-22732, and CVE-2026-34263. In April, cybersecurity firms Aikido and Socket disclosed that attackers had compromised multiple official SAP npm packages in a supply-chain attack aimed at stealing credentials from developers' systems.

Since November 2021 the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog, including three that were abused in ransomware attacks. That history is part of the operational context for defenders and regulators watching new high-severity SAP flaws.

What this means for technologists, procurement leaders, and policymakers

  • Technologists and security teams: The near-immediate targeting reported by Defused places a premium on fast patch validation and deployment for Commerce Cloud tenants running the Data Hub Adapter. The advisory language that an unauthenticated attacker can exploit a default authentication client increases urgency for teams to confirm whether their installations use the vulnerable extension or default clients and to apply SAP's fixes.
  • Procurement and enterprise leaders: Organizations that rely on Commerce Cloud — particularly online stores for major brands and large retailers — must weigh operational risk from rapid exploitation alongside recent supply-chain incidents such as the April npm compromise reported by Aikido and Socket. Procurement and vendor-risk teams will likely seek confirmation of patching and supply-chain controls from SAP and third-party integrators.
  • Policymakers and regulators: Given that CISA has previously added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog and that three prior SAP flaws were used in ransomware attacks, regulators and incident response bodies will be watching whether CVE-2026-58231 becomes categorized as actively exploited and whether additional guidance or listings are issued.

Two concrete facts frame the near-term picture: SAP-issued patches were available, and within three days at least one threat intelligence provider observed exploitation attempts hitting honeypots. Whether those probes translate into widespread compromise of live Commerce Cloud installations — and whether SAP will update its advisory to flag active exploitation — are immediate next data points for defenders, enterprise risk managers, and incident response authorities to monitor.

Source: BleepingComputer — Max severity SAP Commerce Cloud flaw now targeted in attacks