According to threat intelligence organizations, hackers began exploiting a critical vulnerability in SAP Commerce Cloud just three days after it was made public.
The vulnerability is tracked as CVE-2026-58231 and is described as an issue with inadequate authorization checks and input validation.
An attacker could exploit the vulnerability with a CVSS score of 10 to execute arbitrary code and compromise internal components.
SAP announced patches for CVE-2026-58231 on August 11, and Defused reported that its honeypots were visible Exploitation attempts on August 14th. The security company noted that there has been no public PoC exploit and no previous reports of an exploit in the wild.
KEVIntel, which uses proprietary sensors and private honeypots to independently monitor exploitation attempts confirmed See attacks.
The organization noted on August 15 that a PoC exploit had become available.
Known CISA Exploited Vulnerabilities (KEV) catalog currently contains 14 SAP product bugs, but only one of them, CVE-2019-0344, affects Commerce Cloud. The security vulnerability was added to the KEV list in 2024.
CISA has not yet added CVE-2026-58231 to its catalog.
Related: Adobe Commerce bug fixed immediately after disclosure
Related: Fortune 500 companies hit by Azure data theft campaign
Related: Critical flaws discovered in Belgian eID software used by 2 million people
Related: Hackers exploit unpatched GeoServer zero-day
