discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.

By Sergiu Gatlan·Aug 14·bleepingcomputer.com·2 min read

Intelligence analysis by Llama

Max severity SAP Commerce Cloud flaw now targeted in attacks
Image: bleepingcomputer.com

A critical flaw in SAP Commerce Cloud is being exploited by attackers, despite being patched just three days ago. The vulnerability, tracked as CVE-2026-58231, allows unauthenticated attackers to execute arbitrary code and compromise internal components.

Why it matters

This story matters to someone following Security because it highlights the importance of timely patching and the potential consequences of exploiting a critical vulnerability.

Imagine you have a super powerful computer that can do anything you want. But, someone else can also use that computer to do bad things if they know the right password. That's what's happening with SAP Commerce Cloud. A bad guy found a way to use the computer without needing a password, and now they're trying to use it to do bad things.

Analysis

SAP Commerce Cloud Vulnerability Overview

SAP Commerce Cloud is a cloud-based e-commerce platform used by online stores owned by high-profile global brands and large retailers. A maximum-severity remote code execution vulnerability, tracked as CVE-2026-58231, was patched three days ago. However, threat intelligence company Defused has confirmed that the vulnerability is now being targeted in the wild.

Exploitation Attempts

Defused security researchers have detected exploitation attempts against CVE-2026-58231 in their honeypots. The vulnerability has no public proof of concept (PoC) and is not known to be exploited. Despite this, the fact that attackers are already targeting the vulnerability highlights the importance of timely patching.

SAP Commerce Cloud Instances

Internet security watchdog group Shadowserver tracks over 4,200 IP addresses with a SAP Commerce Cloud fingerprint. Most of these IP addresses are from Europe and North America. However, there is no information on how many of them are honeypots or have already been secured against CVE-2026-58231 attacks.

SAP Security Patch Package

SAP fixed 16 vulnerabilities in its July 2026 Security Patch package and 30 more vulnerabilities in June and May. This includes three more critical security flaws affecting the Commerce Cloud enterprise-grade e-commerce platform. In April, cybersecurity companies Aikido and Socket reported that attackers aiming to steal credentials from developers' systems compromised multiple official SAP npm packages in a supply chain attack.

CISA's Known Exploited Vulnerabilities Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog, including three that were abused in ransomware attacks. SAP is a German multinational software corporation that serves 99 of the 100 largest companies worldwide and has reported total revenues exceeding €36 billion in fiscal year 2025.

Key points

  • A maximum-severity SAP Commerce Cloud remote code execution vulnerability was patched three days ago.
  • The vulnerability, tracked as CVE-2026-58231, allows unauthenticated attackers to execute arbitrary code and compromise internal components.
  • Threat intelligence company Defused has confirmed that the vulnerability is now being targeted in the wild.
  • SAP fixed 16 vulnerabilities in its July 2026 Security Patch package and 30 more vulnerabilities in June and May.
  • The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 14 SAP vulnerabilities to its Known Exploited Vulnerabilities catalog.
The Upside

If this development plays out positively, SAP will be able to quickly patch the vulnerability and prevent further exploitation. This will help to protect the online stores and customers who use SAP Commerce Cloud.

The Downside

If this development plays out negatively, the vulnerability will be exploited further, and more customers will be affected. This could lead to significant financial losses and damage to the reputation of SAP and its customers.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritysap-commerce-cloudvulnerabilityremote-code-executionexploitation

Author

Sergiu Gatlan

Intelligence analysis by

Llama

Published

Aug 14, 2026

Source

bleepingcomputer.com

Share

Topics

securitysap-commerce-cloudvulnerabilityremote-code-executionexploitation

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.