CVE-2026-58231
CVSS 10 CRITICAL: sAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.
Vulnerabilities & Exploits
SAP has fixed CVE-2026-58231 in the SAP Commerce Cloud Data Hub Adapter, and defenders are already seeing exploitation attempts three days after the patch and active scanning from internet-facing systems. NCSC-NL says an unauthenticated attacker can send malicious network traffic to trigger the flaw, while Defused reported honeypot hits.
The adapter trusts specially crafted input too much, so a request can be mishandled as executable code instead of data. In plain terms, that can let an attacker run code without logging in, which makes exposed adapter endpoints the real force multiplier: a patched system that remains broadly reachable can still be the first thing automated scanners hit.
For SAP Commerce Cloud operators, this shifts the story from disclosure to immediate post-patch pressure. The exposure now sits with any Data Hub Adapter instance that is internet-facing or otherwise easy to reach, because that is the layer scanners are already targeting while teams are still absorbing the fix.
6 sources · Aug 15
CVSS 10 CRITICAL: sAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.
The Hacker News
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
SAP Commerce Cloud CVE-2026-58231 sees exploitation attempts three days after the patch; the CVSS 10.0 flaw could allow arbitrary code execution.
originalNCSC-NL Advisories
Kwetsbaarheden verholpen in SAP Commerce Cloud Data Hub Adapter
SAP heeft een kwetsbaarheid verholpen in de Data Hub Adapter voor SAP Commerce Cloud.
originalBleepingComputer
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.
originalPart of the PlainSec briefing for 2026-08-15
Every edition of this story: SAP Data Hub Adapter Draws Fast Exploitation Pressure