Exploited in the wild SAP Commerce Cloud rce SAP cloud
Max severity SAP Commerce Cloud flaw now targeted in attacks
CVE Tools coverage
Threat intelligence firm Defused reports that a critical remote code execution vulnerability in SAP Commerce Cloud is being actively targeted despite having only recently been patched. Tracked as CVE-2026-58231 with a maximum CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code by abusing a default authentication client within the Data Hub Adapter extension. Although SAP has not yet updated its official advisory to confirm widespread exploitation, shadow server data indicates over 4,200 internet-exposed instances remain vulnerable across Europe and North America. Organizations should apply the latest security fixes immediately to mitigate the risk of system compromise.