A critical vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231 with a CVSS score of 10.0, is currently being exploited by attackers. This flaw allows unauthenticated users to abuse default authentication methods to execute arbitrary code due to insufficient authorization checks and input validation. Exploitation attempts were recorded within three days of SAP releasing a patch, highlighting the urgency for users to secure their systems. The identity of the attackers remains unknown, but past incidents have linked similar vulnerabilities to China-affiliated APT groups.
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
securityaffairs.com
-
SAP Commerce Cloud flaw lets attackers run arbitrary code
cybersixt.com
-
SAP patches critical CVE-2026-58231 in Commerce Cloud, 28 notes
cybersixt.com
-
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
cybersixt.com