HACKERS are exploiting a critical vulnerability in SAP Commerce Cloud (CVE-2026-58231), identified shortly after its public disclosure. This vulnerability, which has a CVSS score of 10 due to insufficient authorization checks, enables arbitrary code execution. Patches were released on August 11, but by August 14, reports of exploitation attempts were confirmed by various threat intelligence organizations.
This security flaw is yet to be included in CISA's Known Exploited Vulnerabilities catalog, which lists 14 SAP product flaws, with only one impacting Commerce Cloud (CVE-2019-0344). An available proof-of-concept exploit may further increase the risk of exploitation.