Search
Find merged stories by title or summary.
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
The vulnerability tracked as CVE-2026-58231 can be exploited to execute arbitrary code and compromise internal components. The post Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure appeared first on SecurityWeek .
Hackers Exploit Attempts Target Critical SAP Commerce Cloud RCE Flaw
Threat actors have begun actively probing for a maximum-severity vulnerability in SAP Commerce Cloud only three days after security updates were released, signaling an urgent risk for organizations operating internet-exposed commerce environments. The vulnerability, tracked as CVE-2026-58231, has received a CVSS severity score of 10.0, the highest possible rating for an enterprise software flaw. The issue could allow unauthenticated attackers to execute arbitrary code remotely over a network, without valid credentials, user interaction, or prior access to the affected environment. Critical SAP Commerce Cloud RCE Flaw Security researchers at Defused detected the first observed exploitation attempts through honeypot telemetry.
Security Affairs newsletter Round 590 by Pierluigi Paganini – INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. Crooks Are Buying Your Expired Domains and Using Them to Deliver Malware SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild macOS Screen Sharing Flaw Exploited to Deploy Monero Miners GeoServer Zero-Day Is Already Being Probed. That’s the Problem Apple warned hundreds of users of mercenary spyware attacks AmnesiaStealer Gives Attackers Live Control of Victims’ macOS Browsers Chess. com Leak Exposes 7. 3 Million Users – Evidence Points to Scraping US Authorizes Private Cyber Firms to Hack Transnational Criminal Networks Adobe Commerce CVE-2026-71362 Comes Under Attack Shortly After Public Disclosure U. S.
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10. 0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. “SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.” reads the advisory. “Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.”
Hackers Started to Exploit Critical SAP Commerce Cloud, Still No Public PoC
Threat actors have begun actively probing and attempting to exploit a maximum-severity flaw in SAP Commerce Cloud, just three days after official security fixes were released. Defused honeypot telemetry captured the first wave of unauthenticated remote-execution traffic circulating across the web, despite the complete absence of a public proof of concept. Tracked as CVE-2026-58231 , the security defect carries a critical CVSS score of 10. 0, representing the highest possible severity rating for enterprise software. The vulnerability enables unauthenticated adversaries to execute arbitrary code remotely over the network without requiring user interaction or existing privileges.
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts. The vulnerability, tracked as CVE-2026-58231, is rated 10. 0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10. 0 on the CVSS scoring system. It has been described as a case of insufficient authorization checks and input validation. "SAP Commerce Cloud allows an
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
A currently exploited zero-day elevation of privilege vulnerability that needs to be patched in a Windows driver for WinSock is the highlight of the 398 fixes issued today in Microsoft’s August Patch Tuesday releases. The hole is in Windows’ Ancillary Function Driver for WinSock ( CVE-2026-68820 ), which, according to Todd Schell , principal product manager at Ivanti, has been a recurring target for local privilege-escalation bugs throughout 2026. Past vulnerabilities in this component have let an authorized attacker win a race condition to gain SYSTEM privileges. “Exploitation has already been detected,” noted Jack Bicer , director of vulnerability research at Action1, “making this the highest priority vulnerability in this month’s release.” Separately, SAP issued 29 new and updated security patches, the most severe of which is CVE-2026-58231 , with a CVSS score of 10.
CVE-2026-58231 - National Institute of Standards and Technology (.gov)
CVE-2026-58231 National Institute of Standards and Technology (.gov)
You've reached the end of current stories for this search.
