Vulnerabilities · 44 days ago

SAP Data Hub Adapter Draws Fast Exploitation Pressure

SAP has fixed CVE-2026-58231 in the SAP Commerce Cloud Data Hub Adapter, and defenders are already seeing exploitation attempts three days after the patch and active scanning from internet-facing systems. NCSC-NL says an unauthenticated attacker can send malicious network traffic to trigger the flaw, while Defused reported honeypot hits.

The adapter trusts specially crafted input too much, so a request can be mishandled as executable code instead of data. In plain terms, that can let an attacker run code without logging in, which makes exposed adapter endpoints the real force multiplier: a patched system that remains broadly reachable can still be the first thing automated scanners hit.

For SAP Commerce Cloud operators, this shifts the story from disclosure to immediate post-patch pressure. The exposure now sits with any Data Hub Adapter instance that is internet-facing or otherwise easy to reach, because that is the layer scanners are already targeting while teams are still absorbing the fix.

CVE-2026-58231

NVD KEV

CVSS 10 CRITICAL: sAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.

Timeline

Sources

6 sources covering this story

Entities

Part of the PlainSec briefing for 2026-08-16

Editions

Related stories