CVE-2026-58231
CVSS 10 CRITICAL: sAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.
Vulnerabilities · 44 days ago
SAP has fixed CVE-2026-58231 in the SAP Commerce Cloud Data Hub Adapter, and defenders are already seeing exploitation attempts three days after the patch and active scanning from internet-facing systems. NCSC-NL says an unauthenticated attacker can send malicious network traffic to trigger the flaw, while Defused reported honeypot hits.
The adapter trusts specially crafted input too much, so a request can be mishandled as executable code instead of data. In plain terms, that can let an attacker run code without logging in, which makes exposed adapter endpoints the real force multiplier: a patched system that remains broadly reachable can still be the first thing automated scanners hit.
For SAP Commerce Cloud operators, this shifts the story from disclosure to immediate post-patch pressure. The exposure now sits with any Data Hub Adapter instance that is internet-facing or otherwise easy to reach, because that is the layer scanners are already targeting while teams are still absorbing the fix.
CVSS 10 CRITICAL: sAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.
6 sources covering this story
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
SAP Commerce Cloud CVE-2026-58231 sees exploitation attempts three days after the patch; the CVSS 10.0 flaw could allow arbitrary code execution.
Kwetsbaarheden verholpen in SAP Commerce Cloud Data Hub Adapter
SAP heeft een kwetsbaarheid verholpen in de Data Hub Adapter voor SAP Commerce Cloud.
Max severity SAP Commerce Cloud flaw now targeted in attacks
A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.
Adobe Commerce Bug Targeted Immediately After Disclosure
The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches.
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts.
Kwetsbaarheden verholpen in Adobe ColdFusion
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe ColdFusion versies 2025.0.11, 2023.0.22 en eerdere versies. De kwetsbaarheden in Adobe ColdFusion kunnen door ongeauthenticeerde kwaadwillenden worden misbruikt om willekeurige code uit te voeren op afstand, beveiligingsmaatregelen te omzeilen, rechten te verhogen op het systeem of middels DoS de werking...
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe patches seven ColdFusion, Commerce, and Campaign Classic flaws that could enable code execution, privilege escalation, or denial-of-service.
Adobe: aggiornamenti di sicurezza
Adobe ha rilasciato aggiornamenti di sicurezza per risolvere molteplici vulnerabilità, di cui 7 con gravità “critica” e 27 con gravità “alta”, nei prodotti Commerce, Magento, ColdFusion, Campaign Classic, Lightroom Classic, Content Credentials Rust SDK, C2PA Tool, Content Credentials JS SDK.
Kwetsbaarheden verholpen in Adobe Commerce
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Commerce.
Kwetsbaarheden verholpen in Adobe Campaign Classic
Adobe heeft kwetsbaarheden verholpen in Adobe Campaign Classic. De kwetsbaarheden maken het mogelijk voor een aanvaller om zonder gebruikersinteractie willekeurige code uit te voeren. Eén van de kwetsbaarheden betreft een onjuiste autorisatie, waardoor een aanvaller acties kan uitvoeren buiten de bedoelde permissies. Een andere kwetsbaarheid betreft een...
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP fixes CVE-2026-58231, a CVSS 10.0 Commerce Cloud flaw that could let unauthenticated attackers execute arbitrary code.
Actualización de seguridad de SAP de agosto de 2026
SAP ha publicado su boletín mensual en el que se incluyen 29 vulnerabilidades: 4 de severidad crítica
Part of the PlainSec briefing for 2026-08-16