INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
| 2026-08-15 08:38 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, has been exploited in the wild just days after a patch was released. This critical security flaw is rated 10.0 on the CVSS scoring system and allows for arbitrary code execution and compromise of internal components. Prior flaws impacting SAP products, including NetWeaver, have also been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. The vulnerability has no public proof of concept and is not known to be exploited, but threat intelligence company Defused Cyber says it could permit arbitrary code execution and compromise internal components. Successful exploitation efforts have been detected on August 14 from a lone IP address located in the U.S., with two attempts already seen since April 2025.
Technical Mitigations AI-generated
* Configure an IP Filter Set in SAP Commerce Cloud to restrict access to the vulnerable endpoint and reduce exposure to potential attackers.
* Ensure that all instances of SAP Commerce Cloud are patched to the fixed Commerce Cloud release levels referenced in the advisory, and re-build or redeploy the updated SAP Commerce Cloud version as soon as possible.
* Implement a secure coding practice for input validation and authorization checks to prevent exploitation of this vulnerability.
* Monitor system logs and network traffic for signs of unauthorized access or activity related to CVE-2026-58231, and take prompt action if any suspicious activity is detected.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected
Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.
hxxp://••••••••••••••••••••
me•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-44761CVE-2026-44761
CVE-2025-31324CVE-2025-31324
CVE-2026-44758CVE-2026-44758
CVE-2026-34265CVE-2026-34265
CVE-2026-58231CVE-2026-58231
CVE-2026-44772CVE-2026-44772
CVE-2026-34263CVE-2026-34263
CVE-2026-22732CVE-2026-22732
Target & Sectors
DACH
DACH
NORTH_AMERICA
NORTH_AMERICA
retailretail
technologytechnology
Incident Timeline
November 2021
Threat actors used a known exploited vulnerability in SAP Commerce Cloud to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
Click on any entity below to view its context and source!
tactic
Ransomware
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has added 14 SAP vulnerabilities
to its Known Exploited Vulnerabilities catalog, including three that were abused in ransomware attacks.
attribution
Known Exploited
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has added 14 SAP vulnerabilities
to its Known Exploited Vulnerabilities catalog, including three that were abused in ransomware attacks.
tactic
T1588.006 - Vulnerabilities
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has added 14 SAP vulnerabilities
to its Known Exploited Vulnerabilities catalog, including three that were abused in ransomware attacks.
general_metric
14 SAP vulnerabilities
Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA)
has added 14 SAP vulnerabilities
to its Known Exploited Vulnerabilities catalog, including three that were abused in ransomware attacks.
April 2025
Threat actors exploited SAP NetWeaver CVE-2026-58231 to deploy a backdoor called Auto-Color in an attack targeting a U.S.-based chemicals company.
Click on any entity below to view its context and source!
organisation
SAP NetWeaver
In April 2025, unknown threat actors were also
observed
exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color in an attack aimed at a U.S.-based chemicals company.
organisation
Auto-Color
In April 2025, unknown threat actors were also
observed
exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color in an attack aimed at a U.S.-based chemicals company.
fiscal year 2025
Threat actors exploited CVE-2026-58231 in SAP Commerce Cloud targeting 99 of the 100 largest companies worldwide.
Click on any entity below to view its context and source!
target_region
Germany
SAP is a German multinational software corporation that serves 99 of the 100 largest companies worldwide and has reported total revenues exceeding €36 billion in fiscal year 2025.
general_metric
99 corporation
SAP is a German multinational software corporation that serves 99 of the 100 largest companies worldwide and has reported total revenues exceeding €36 billion in fiscal year 2025.
general_metric
100 largest companies
SAP is a German multinational software corporation that serves 99 of the 100 largest companies worldwide and has reported total revenues exceeding €36 billion in fiscal year 2025.
financial
€36 revenues
SAP is a German multinational software corporation that serves 99 of the 100 largest companies worldwide and has reported total revenues exceeding €36 billion in fiscal year 2025.
July 2026
SAP fixed 16 vulnerabilities in its July 2026 Security Patch package and 30 more vulnerabilities in June, May, and July.
Click on any entity below to view its context and source!
organisation
SAP Commerce Cloud
Internet-exposed SAP Commerce Cloud instances (Shadowserver)
Most recently, SAP
fixed 16 vulnerabilities
in its July 2026 Security Patch package and 30 more vulnerabilities in
June
and
May
, including three more critical security flaws (
CVE-2026-44761
,
CVE-2026-22732
, and
CVE-2026-34263
) affecting the Commerce Cloud enterprise-grade e-commerce platform.
vulnerability
CVE-2026-44761
Internet-exposed SAP Commerce Cloud instances (Shadowserver)
Most recently, SAP
fixed 16 vulnerabilities
in its July 2026 Security Patch package and 30 more vulnerabilities in
June
and
May
, including three more critical security flaws (
CVE-2026-44761
,
CVE-2026-22732
, and
CVE-2026-34263
) affecting the Commerce Cloud enterprise-grade e-commerce platform.
vulnerability
CVE-2026-22732
Internet-exposed SAP Commerce Cloud instances (Shadowserver)
Most recently, SAP
fixed 16 vulnerabilities
in its July 2026 Security Patch package and 30 more vulnerabilities in
June
and
May
, including three more critical security flaws (
CVE-2026-44761
,
CVE-2026-22732
, and
CVE-2026-34263
) affecting the Commerce Cloud enterprise-grade e-commerce platform.
vulnerability
CVE-2026-34263
Internet-exposed SAP Commerce Cloud instances (Shadowserver)
Most recently, SAP
fixed 16 vulnerabilities
in its July 2026 Security Patch package and 30 more vulnerabilities in
June
and
May
, including three more critical security flaws (
CVE-2026-44761
,
CVE-2026-22732
, and
CVE-2026-34263
) affecting the Commerce Cloud enterprise-grade e-commerce platform.
organisation
Commerce
Internet-exposed SAP Commerce Cloud instances (Shadowserver)
Most recently, SAP
fixed 16 vulnerabilities
in its July 2026 Security Patch package and 30 more vulnerabilities in
June
and
May
, including three more critical security flaws (
CVE-2026-44761
,
CVE-2026-22732
, and
CVE-2026-34263
) affecting the Commerce Cloud enterprise-grade e-commerce platform.
general_metric
16 vulnerabilities
Internet-exposed SAP Commerce Cloud instances (Shadowserver)
Most recently, SAP
fixed 16 vulnerabilities
in its July 2026 Security Patch package and 30 more vulnerabilities in
June
and
May
, including three more critical security flaws (
CVE-2026-44761
,
CVE-2026-22732
, and
CVE-2026-34263
) affecting the Commerce Cloud enterprise-grade e-commerce platform.
general_metric
30 more vulnerabilities
Internet-exposed SAP Commerce Cloud instances (Shadowserver)
Most recently, SAP
fixed 16 vulnerabilities
in its July 2026 Security Patch package and 30 more vulnerabilities in
June
and
May
, including three more critical security flaws (
CVE-2026-44761
,
CVE-2026-22732
, and
CVE-2026-34263
) affecting the Commerce Cloud enterprise-grade e-commerce platform.
Aug 12, 2026
Threat actors exploited CVE-2026-58231 in the wild on August 12, 2026.
August 14
Threat actors used a known vulnerability in SAP Commerce Cloud CVE-2026-58231 to target the affected system.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-58231
Update
KEVIntel has also
independently confirmed
seeing exploitation efforts against CVE-2026-58231, with two attempts detected on August 14 from a lone IP address located in the U.S.
organisation
Update
Update
KEVIntel has also
independently confirmed
seeing exploitation efforts against CVE-2026-58231, with two attempts detected on August 14 from a lone IP address located in the U.S.
Update August 14, 11:51 EDT: Added SAP statement.
organisation
KEVIntel
Update
KEVIntel has also
independently confirmed
seeing exploitation efforts against CVE-2026-58231, with two attempts detected on August 14 from a lone IP address located in the U.S.
organisation
IP
Update
KEVIntel has also
independently confirmed
seeing exploitation efforts against CVE-2026-58231, with two attempts detected on August 14 from a lone IP address located in the U.S.
2026/08/14
Threat actors used a known vulnerability in SAP Commerce Cloud to target the affected software.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-58231
"
While SAP has yet to flag this security flaw as actively exploited in a
security advisory
issued this Tuesday, Defused security researchers confirmed earlier today that CVE-2026-58231 is now being targeted in the wild.
organisation
Defused
"
While SAP has yet to flag this security flaw as actively exploited in a
security advisory
issued this Tuesday, Defused security researchers confirmed earlier today that CVE-2026-58231 is now being targeted in the wild.
Aug 15, 2026
Threat actors exploited CVE-2026-58231 in the wild against SAP Commerce Cloud.
2026/08/15
Threat actors exploited a maximum-severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231.
Click on any entity below to view its context and source!
organisation
SAP
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by
China-nexus espionage clusters
like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as
BianLian and RansomExx
.
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild.
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch.
"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," SAP explains.
Ravie Lakshmanan
Aug 12, 2026
Enterprise Security / Vulnerability
SAP has
released patches
to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution.
organisation
NetWeaver
However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by
China-nexus espionage clusters
like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as
BianLian and RansomExx
.
organisation
APT
However, previous critical SAP flaws have been exploited by China-linked APT groups, including
UNC5221
and
UNC5174
, and ransomware gangs.
organisation
SAP Commerce
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild.
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch.
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch.
organisation
SAP Commerce Cloud
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild.
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch.
Ravie Lakshmanan
Aug 15, 2026
Vulnerability / Cloud Security
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.
"Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application."
SAP security company Onapsis has
urged
customers to patch to a fixed Commerce Cloud release and then re-deploy the updated SAP Commerce Cloud version.
organisation
CVSS
The vulnerability, tracked as
CVE-2026-58231
, is rated 10.0 on the CVSS scoring system.
The vulnerability, assigned the CVE identifier
CVE-2026-58231
, is rated 10.0 on the CVSS scoring system.
infrastructure
10.0
A critical SAP Commerce Cloud vulnerability, tracked as
CVE-2026-58231
(CVSS score of 10.0), is under active exploitation just days after SAP released a patch.
organisation
Data Hub Adapter
Tracked as
CVE-2026-58231
, this critical flaw stems from an improper authorization weakness in the core Data Hub Adapter extension for Commerce Cloud that threat actors without privileges can exploit in low-complexity attacks to execute arbitrary code.
organisation
CVE
The vulnerability, assigned the CVE identifier
CVE-2026-58231
, is rated 10.0 on the CVSS scoring system.
organisation
IP
Internet security watchdog group Shadowserver tracks
over 4,200 IP addresses with a SAP Commerce Cloud fingerprint
, most of them from Europe and North America.
infrastructure
4,200 IP addresses
Internet security watchdog group Shadowserver tracks
over 4,200 IP addresses with a SAP Commerce Cloud fingerprint
, most of them from Europe and North America.
organisation
Vulnerability / Cloud Security
Ravie Lakshmanan
Aug 15, 2026
Vulnerability / Cloud Security
A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.
organisation
Commerce
"Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application."
SAP security company Onapsis has
urged
customers to patch to a fixed Commerce Cloud release and then re-deploy the updated SAP Commerce Cloud version.
organisation
The Blue Report 2026
The Blue Report 2026 measures defenses technique by technique across 338 million simulations run in customer production environments.
organisation
SecurityAffairs
Follow me on Twitter:
@securityaffairs
and
Facebook
and
Mastodon
Pierluigi Paganini
(
SecurityAffairs
– hacking, SAP Commerce Cloud)
organisation
BleepingComputer
"
A SAP spokesperson told BleepingComputer that the company is aware of and investigating this issue when asked to confirm Defused's report.
organisation
SAP’s
"A security note
is published and available for SAP customers and partners and was released on SAP’s August Patch Day.
organisation
Socket
In April, cybersecurity companies Aikido and Socket also reported that attackers aiming to steal credentials from developers' systems compromised multiple official SAP npm packages
in a supply chain attack
.
organisation
CVE-2026
CVE-2026-44772 patches a vulnerable servlet that allows a low-privileged attacker to submit specially crafted input that causes the application to fetch and process attacker-controlled content from an external source, ultimately leading to arbitrary command execution on the underlying host.
organisation
CVE-2026-44758
CVE-2026-44758
(CVSS score: 9.1) -
organisation
SSTI
Per Onapsis, CVE-2026-44758 plugs an issue with a servlet component that's susceptible to server-side template injection (SSTI) and server-side request forgery (SSRF), which could pave the way for command execution.
organisation
CVE.org
"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," according to a description of the flaw on CVE.org.
organisation
ABAP Platform
An out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform that allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption.
organisation
DIAG
An out-of-bounds write vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform that allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption.
organisation
XSL
"After implementing the patch, customers need to maintain the new system property 'Secure Transformer' with a list of allowed hosts for hosting XSL files," it said.
2026/08/17
Threat actors used a vulnerability exploit in SAP Commerce Cloud to target the system, with an initial CVSS score of 10.0.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-58231
CVE-2026-58231 exploitation attempt (Defused)
"First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day,"
Defused warned
in a Friday tweet.
vulnerability
CVSS score of 10.0
CVE-2026-58231 exploitation attempt (Defused)
"First exploitation attempts against CVE-2026-58231 (unauth RCE in SAP Commerce Cloud, CVSS 10.0) is now hitting our honeypots - 3 days after patch day,"
Defused warned
in a Friday tweet.
August 2026
Threat actors exploited CVE-2026-58231 in the wild.
Click on any entity below to view its context and source!
vulnerability
CVE-2026-44772
SAP has also addressed three other critical flaws as part of its August 2026 update -
CVE-2026-44772
(CVSS score: 9.9) -
infrastructure
9.9
SAP has also addressed three other critical flaws as part of its August 2026 update -
CVE-2026-44772
(CVSS score: 9.9) -
general_metric
9.9 score
SAP has also addressed three other critical flaws as part of its August 2026 update -
CVE-2026-44772
(CVSS score: 9.9) -
Tactical Metrics
Metrics
infrastructure
10.0
Software Version
Click for context!
A critical SAP Commerce Cloud vulnerability, tracked as
CVE-2026-58231
(CVSS score of 10.0), is under active exploitation just days after SAP released a patch.
Metrics
infrastructure
4,200
Ip Addresses
Internet security watchdog group Shadowserver tracks
over 4,200 IP addresses with a SAP Commerce Cloud fingerprint
, most of them from Europe and North America.
Metrics
financial
36,000,000,000
Revenues
SAP is a German multinational software corporation that serves 99 of the 100 largest companies worldwide and has reported total revenues exceeding €36 billion in fiscal year 2025.
Metrics
infrastructure
9.9
Software Version
SAP has also addressed three other critical flaws as part of its August 2026 update -
CVE-2026-44772
(CVSS score: 9.9) -
Intelligence Sources
Security Affairs
2026-08-15
SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild
Security Affairs
The Hacker News
2026-08-15
The Hacker News
2026-08-12
BleepingComputer
2026-08-14
Max severity SAP Commerce Cloud flaw now targeted in attacks
BleepingComputer
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-08-18T06:01
Comprehensive Tactical Telemetry
Highly Correlated Entities
28x
organisation
Identified Entity
SAP
entity
12x
timeline
Temporal Reference
Aug 15, 2026
date
8x
vulnerability
Exploited CVE
CVE-2025-31324
cve
6x
attribution
Attributing Entity
SAP
authority
3x
tactic
Cyber Operation Type
Espionage
tactic
3x
general metric
Aug
15
aug
2x
infrastructure
Software Version
10.0
version
2x
tactic
MITRE ATT&CK Technique
T1588.006 - Vulnerabilities
technique
2x
target region
Target Region
EUROPE
region
Contextual Telemetry
Context Block
15 METRICS
source region
Origin Country
China
country
vulnerability
CVSS Score
10
score
general metric
Sap Vulnerabilities
14
sap vulnerabilities
infrastructure
Ip Addresses
4,200
ip addresses
general metric
Vulnerabilities
16
vulnerabilities
general metric
More Vulnerabilities
30
more vulnerabilities
target region
Target Country
Germany
country
general metric
Corporation
99
corporation
general metric
Largest Companies
100
largest companies
financial
Revenues
36,000,000,000
revenues
general metric
Simulations
338,000,000
simulations
industry
Targeted Sector
Manufacturing
sector
general metric
Injection Vulnerability
10
injection vulnerability
general metric
Score
10
score
general metric
Cvss Score
9
cvss score
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.