CVE-2026-58231
CVSS 10 CRITICAL: sAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.
Vulnerabilità · 44 giorni fa
In SAP Commerce Cloud il punto debole non è più solo la falla: sono gli endpoint del Data Hub Adapter esposti, che vengono raggiunti da traffico ostile appena dopo la patch. Quando il servizio accetta input strutturati senza validarli a dovere, una richiesta appositamente costruita può passare da dato a codice eseguibile.
SAP ha corretto CVE-2026-58231 nel Data Hub Adapter; il NCSC olandese segnala che Defused ha già visto tentativi di sfruttamento sui suoi honeypot a tre giorni dal rilascio della patch, e che gli attaccanti stanno già scansionando sistemi vulnerabili. La falla è classificata come code injection e permette a un attaccante non autenticato di arrivare a arbitrary code execution.
Per chi gestisce SAP Commerce Cloud, il messaggio è che la finestra critica si apre subito dopo il rilascio delle fix e si concentra sui componenti raggiungibili dall’esterno. Anche un sistema già aggiornato resta un bersaglio immediato finché l’endpoint vulnerabile rimane esposto o troppo ampio nella superficie di accesso.
CVSS 10 CRITICAL: sAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.
6 fonti che coprono questa storia
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
SAP Commerce Cloud CVE-2026-58231 sees exploitation attempts three days after the patch; the CVSS 10.0 flaw could allow arbitrary code execution.
Kwetsbaarheden verholpen in SAP Commerce Cloud Data Hub Adapter
SAP heeft een kwetsbaarheid verholpen in de Data Hub Adapter voor SAP Commerce Cloud.
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.
Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
Kwetsbaarheden verholpen in Adobe ColdFusion
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe ColdFusion versies 2025.0.11, 2023.0.22 en eerdere versies. De kwetsbaarheden in Adobe ColdFusion kunnen door ongeauthenticeerde kwaadwillenden worden misbruikt om willekeurige code uit te voeren op afstand, beveiligingsmaatregelen te omzeilen, rechten te verhogen op het systeem of middels DoS de werking...
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe patches seven ColdFusion, Commerce, and Campaign Classic flaws that could enable code execution, privilege escalation, or denial-of-service.
Adobe: aggiornamenti di sicurezza
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 7 con gravità “critica” e 27 con gravità “alta”, nei prodotti Commerce, Magento, ColdFusion, Campaign Classic, Lightroom Classic, Content Credentials Rust SDK, C2PA Tool, Content Credentials JS SDK.
Kwetsbaarheden verholpen in Adobe Commerce
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Commerce.
Kwetsbaarheden verholpen in Adobe Campaign Classic
Adobe heeft kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden maken het mogelijk voor een aanvaller om zonder gebruikersinteractie willekeurige code uit te voeren. Eén van de kwetsbaarheden betreft een onjuiste autorisatie, waardoor een aanvaller acties kan uitvoeren buiten de bedoelde permissies. Een andere kwetsbaarheid betreft een...
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP fixes CVE-2026-58231, a CVSS 10.0 Commerce Cloud flaw that could let unauthenticated attackers execute arbitrary code.
Actualización de seguridad de SAP de agosto de 2026
SAP ha publicado su boletín mensual en el que se incluyen 29 vulnerabilidades: 4 de severidad crítica
Part of the PlainSec briefing for 2026-08-16