securityaffairs.com 8/15/2026, 5:40:50 PM · external

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Developing story vulnerability 4 articles tracked
SAP Commerce Cloud critical flaw (CVE-2026-58231) exploited in the wild
CyberSIXT Evidence Panel
Primary Source cve.org
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231 with a CVSS score of 10.0, is currently being exploited by attackers. This flaw allows unauthenticated users to abuse default authentication methods to execute arbitrary code due to insufficient authorization checks and input validation. Exploitation attempts were recorded within three days of SAP releasing a patch, highlighting the urgency for users to secure their systems. The identity of the attackers remains unknown, but past incidents have linked similar vulnerabilities to China-affiliated APT groups.

View Primary Source Via securityaffairs.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline