www.securityweek.com 8/17/2026, 8:21:13 AM · external

SAP Commerce Cloud flaw lets attackers run code after patch delay

SAP Commerce Cloud flaw lets attackers run code after patch delay
Developing story vulnerability 6 articles tracked
SAP Commerce Cloud CVE-2026-58231 exploited in the wild
CyberSIXT Evidence Panel
Primary Source cisa.gov
CISA KEV Listed in KEV
Patch Patch Available

HACKERS are exploiting a critical vulnerability in SAP Commerce Cloud (CVE-2026-58231), identified shortly after its public disclosure. This vulnerability, which has a CVSS score of 10 due to insufficient authorization checks, enables arbitrary code execution. Patches were released on August 11, but by August 14, reports of exploitation attempts were confirmed by various threat intelligence organizations.

This security flaw is yet to be included in CISA's Known Exploited Vulnerabilities catalog, which lists 14 SAP product flaws, with only one impacting Commerce Cloud (CVE-2019-0344). An available proof-of-concept exploit may further increase the risk of exploitation.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline