444/69 monday, August 17, 2026

Cybersecurity company Defused Cyber has detected attempts to exploit CVE-2026-58231 in SAP Commerce Cloud after SAP released patches for the vulnerability. The flaw is rated Critical, with a CVSS score of 10.0, and could allow unauthenticated attackers to execute code on affected systems and access internal components of the application.
Reports indicate that the vulnerability is caused by insufficient authentication and input validation. Attackers can exploit the flaw by using a default authentication client together with specially crafted data. Defused Cyber detected these attempts in a honeypot environment. At the time of reporting, no public proof-of-concept (PoC) exploit had been released, and there was no confirmed information indicating successful exploitation.
SAP Commerce Cloud users should update to the fixed versions specified by SAP and rebuild and redeploy their systems. For cases where patches cannot yet be applied, administrators can configure an IP filter set to restrict access to the affected endpoint as a temporary mitigation. Organizations should prioritize remediation, as exploitation attempts have already been observed.
Source: https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html
