CVE Tools
Back to feed
Exploited in the wild SAP Commerce Cloud rce SAP cloud

Max severity SAP Commerce Cloud flaw now targeted in attacks

BleepingComputer·By Sergiu Gatlan··2 min read
CVE Tools coverage

Threat intelligence firm Defused reports that a critical remote code execution vulnerability in SAP Commerce Cloud is being actively targeted despite having only recently been patched. Tracked as CVE-2026-58231 with a maximum CVSS score of 10.0, this flaw allows unauthenticated attackers to execute arbitrary code by abusing a default authentication client within the Data Hub Adapter extension. Although SAP has not yet updated its official advisory to confirm widespread exploitation, shadow server data indicates over 4,200 internet-exposed instances remain vulnerable across Europe and North America. Organizations should apply the latest security fixes immediately to mitigate the risk of system compromise.