Attackers began targeting a critical security vulnerability in the SAP Commerce Cloud platform just three days after its patch was released, according to researchers at threat intelligence company Defused. The vulnerability is tracked as CVE-2026-58231 and has a CVSS severity rating of 10.0, making it one of the most severe vulnerabilities.
Commerce Cloud, formerly known as SAP Hybris, is used as a cloud e-commerce platform by online stores operated by prominent global brands and major retailers. Exploiting the vulnerability could allow an attacker to remotely execute code of their choice and subsequently affect internal platform components.
Privilege-Free Code Execution Vulnerability
The issue stems from an authorization weakness in the core Data Hub Adapter extension in Commerce Cloud. An unauthenticated, unprivileged attacker could exploit it in a low-complexity attack to execute arbitrary code.
SAP explained that an unauthenticated attacker could abuse a default authentication client and send specially crafted inputs to specific functions that do not apply a sufficient level of validation. Successful exploitation could enable arbitrary code execution and compromise internal components, with a high impact on the application's confidentiality, integrity, and availability.
Honeypots Detect Exploitation Attempts
Defused researchers said that the first exploitation attempts began reaching their honeypot systems three days after the patch was released. They confirmed that the vulnerability has no publicly available proof-of-concept exploit and that it was not previously known to be exploited.
In contrast, SAP did not classify the vulnerability as actively exploited in its security bulletin issued on Tuesday. A company spokesperson told BleepingComputer that SAP is aware of and investigating the matter, noting that security note 3771065 was published for customers and partners as part of the August Patch Day. The company recommended that customers and partners install the updates immediately.
More Than 4,200 Addresses Associated with the Platform
The Shadowserver internet security monitoring group tracks more than 4,200 IP addresses bearing an SAP Commerce Cloud fingerprint, most of them concentrated in Europe and North America. No information is available to determine how many of these systems are honeypots or how many systems have already been secured against exploitation of CVE-2026-58231.
This incident comes amid a series of security updates affecting Commerce Cloud. SAP fixed 16 vulnerabilities in the July 2026 security patch bundle, in addition to 30 other vulnerabilities in June and May, including three critical vulnerabilities: CVE-2026-44761, CVE-2026-22732, and CVE-2026-34263.
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 vulnerabilities in SAP products to its Known Exploited Vulnerabilities catalog, including three vulnerabilities used in ransomware attacks. Aikido and Socket also reported in April that attackers sought to steal credentials from developer systems after compromising several official SAP npm packages in a supply chain attack.