Ciberseguridad

Targeting of a Critical SAP Commerce Cloud Vulnerability Three Days After Its Patch

Defused confirmed that attackers began targeting a remote code execution vulnerability in SAP Commerce Cloud, despite there being no publicly available proof-of-concept exploit and SAP not officially announcing that it was being actively exploited. SAP urged its customers and partners to install the security update immediately.

2026-08-14
3 min de lectura
8 visitas
فريق تحرير certi.news
Targeting of a Critical SAP Commerce Cloud Vulnerability Three Days After Its Patch

Attackers began targeting a critical security vulnerability in the SAP Commerce Cloud platform just three days after its patch was released, according to researchers at threat intelligence company Defused. The vulnerability is tracked as CVE-2026-58231 and has a CVSS severity rating of 10.0, making it one of the most severe vulnerabilities.

Commerce Cloud, formerly known as SAP Hybris, is used as a cloud e-commerce platform by online stores operated by prominent global brands and major retailers. Exploiting the vulnerability could allow an attacker to remotely execute code of their choice and subsequently affect internal platform components.

Privilege-Free Code Execution Vulnerability

The issue stems from an authorization weakness in the core Data Hub Adapter extension in Commerce Cloud. An unauthenticated, unprivileged attacker could exploit it in a low-complexity attack to execute arbitrary code.

SAP explained that an unauthenticated attacker could abuse a default authentication client and send specially crafted inputs to specific functions that do not apply a sufficient level of validation. Successful exploitation could enable arbitrary code execution and compromise internal components, with a high impact on the application's confidentiality, integrity, and availability.

Honeypots Detect Exploitation Attempts

Defused researchers said that the first exploitation attempts began reaching their honeypot systems three days after the patch was released. They confirmed that the vulnerability has no publicly available proof-of-concept exploit and that it was not previously known to be exploited.

In contrast, SAP did not classify the vulnerability as actively exploited in its security bulletin issued on Tuesday. A company spokesperson told BleepingComputer that SAP is aware of and investigating the matter, noting that security note 3771065 was published for customers and partners as part of the August Patch Day. The company recommended that customers and partners install the updates immediately.

More Than 4,200 Addresses Associated with the Platform

The Shadowserver internet security monitoring group tracks more than 4,200 IP addresses bearing an SAP Commerce Cloud fingerprint, most of them concentrated in Europe and North America. No information is available to determine how many of these systems are honeypots or how many systems have already been secured against exploitation of CVE-2026-58231.

This incident comes amid a series of security updates affecting Commerce Cloud. SAP fixed 16 vulnerabilities in the July 2026 security patch bundle, in addition to 30 other vulnerabilities in June and May, including three critical vulnerabilities: CVE-2026-44761, CVE-2026-22732, and CVE-2026-34263.

Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 vulnerabilities in SAP products to its Known Exploited Vulnerabilities catalog, including three vulnerabilities used in ransomware attacks. Aikido and Socket also reported in April that attackers sought to steal credentials from developer systems after compromising several official SAP npm packages in a supply chain attack.

Fuente de la noticia
BleepingComputer
Abrir fuente original ↗
ف
Autor

فريق تحرير certi.news

De la misma categoría

También te puede interesar

Ver todas las noticias