Hackers Exploit Attempts Target Critical SAP Commerce Cloud RCE Flaw
Brief
Threat actors have begun actively probing for a maximum-severity vulnerability in SAP Commerce Cloud only three days after security updates were released, signaling an urgent risk for organizations operating internet-exposed commerce environments.
The vulnerability, tracked as CVE-2026-58231, has received a CVSS severity score of 10.0, the highest possible rating for an enterprise software flaw.
The issue could allow unauthenticated attackers to execute arbitrary code remotely over a network, without valid credentials, user interaction, or prior access to the affected environment.
Critical SAP Commerce Cloud RCE Flaw
Security researchers at Defused detected the first observed exploitation attempts through honeypot telemetry.
