CVE-2026-34263: exploitation status and patch state
CVE-2026-34263 · CVSS 9.6 CRITICAL · EPSS 1%
Due to improper Spring Security configuration, SAP Commerce cloud allows an unauthenticated user to perform malicious configuration upload and code injection, resulting in arbitrary server-side code execution, leading to high impact on Confidentiality, Integrity, and Availability of the application.
Is CVE-2026-34263 exploited?
Not in the CISA KEV catalog.
EPSS puts exploitation in the next 30 days at 1%.
Public exploit code: none found in monitored sources.