Attackers began targeting a critical security vulnerability in the SAP Commerce Cloud platform just three days after its patch was released, according to researchers at threat intelligence company Defused. The vulnerability is tracked as CVE-2026-58231 and has a CVSS severity score of 10.0, making it one of the most severe vulnerabilities.
Commerce Cloud, formerly known as SAP Hybris, is used as a cloud e-commerce platform by online stores operated by prominent global brands and major retailers. Exploiting the vulnerability could allow an attacker to execute code of their choice remotely and consequently affect internal platform components.
Unprivileged code execution vulnerability
The issue stems from an authorization weakness in the core Data Hub Adapter extension in Commerce Cloud. An unauthenticated attacker without privileges can exploit it in a low-complexity attack to execute arbitrary code.
SAP explained that an unauthenticated attacker could abuse a default authentication client and send specially crafted inputs to certain functions that do not apply a sufficient level of validation. Successful exploitation could enable arbitrary code execution and compromise internal components, with a high impact on the application's confidentiality, integrity, and availability.
Honeypots detect exploitation attempts
Defused researchers said that the first exploitation attempts began reaching their honeypot systems three days after the patch was released. They confirmed that the vulnerability had no publicly available proof of concept and had not previously been known to be exploited.
In contrast, SAP did not classify the vulnerability as actively exploited in its security bulletin issued Tuesday. A company spokesperson told BleepingComputer that SAP was aware of and investigating the issue, noting that security note 3771065 was published for customers and partners as part of the August Patch Day. The company recommended that customers and partners install the updates immediately.
More than 4,200 addresses associated with the platform
Internet security monitoring group Shadowserver is tracking more than 4,200 IP addresses bearing the SAP Commerce Cloud fingerprint, most of them concentrated in Europe and North America. No information is available indicating how many of these systems are honeypots or how many systems have already been secured against exploitation of CVE-2026-58231.
The incident comes amid a series of security updates affecting Commerce Cloud. SAP fixed 16 vulnerabilities in its July 2026 security patch package, in addition to 30 other vulnerabilities in June and May, including three critical vulnerabilities: CVE-2026-44761, CVE-2026-22732, and CVE-2026-34263.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 vulnerabilities in SAP products to its Known Exploited Vulnerabilities catalog, including three vulnerabilities used in ransomware attacks. Aikido and Socket also reported in April that attackers sought to steal credentials from developer systems after compromising several official SAP npm packages in a supply-chain attack.