SAP Data Hub Adapter Faces Internet Scanning

SAP has patched a critical code-injection flaw in SAP Commerce Cloud Data Hub Adapter, tracked as CVE-2026-58231 and rated CVSS 10.0. NCSC-NL says Defused has reported active scanning for exposed systems. The adapter will accept crafted network traffic from anyone, and the bad input can be treated as legitimate enough to trigger arbitrary code execution. In plain terms, an internet-facing adapter is not just a relay point here; it can become the initial entry point into the commerce environment. That makes exposed Data Hub Adapter instances the immediate concern. If your SAP Commerce Cloud setup includes one, the exposure sits at the network edge, where opportunistic attackers are already looking for it.

Part of the PlainSec briefing for 2026-08-15

Editions

Sources