SAP has patched a maximum-severity vulnerability in SAP Commerce Cloud (Data Hub Adapter), tracked as CVE-2026-58231, that could allow an unauthenticated attacker to achieve arbitrary code execution. The flaw affects COM_CLOUD 2211 and 2211-JDK21 and stems from improper authorization and insufficient input validation, enabling abuse of a default authentication client and specially crafted input to reach vulnerable functions. The issue is classified as CWE-94 and carries a CVSS score of 10.0, with potential impact across confidentiality, integrity, and availability.
SAP and Onapsis urged customers to upgrade to a fixed Commerce Cloud release and redeploy the updated version, while suggesting IP filtering as a temporary mitigation. SAP's broader August security update also addressed three additional critical flaws affecting Manufacturing Integration and Intelligence and Application Server ABAP for SAP NetWeaver and ABAP Platform, including code injection and memory corruption bugs that could lead to command execution, information disclosure, or system crashes.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
KEVIntel reported that a proof-of-concept exploit for SAP Commerce Cloud vulnerability CVE-2026-58231 had become available. This followed observed exploitation attempts and added new public technical detail about the flaw's weaponization.
A new CVE entry, CVE-2026-58231, was recorded for SAP Commerce Cloud (Data Hub Adapter). The flaw affects COM_CLOUD 2211 and 2211-JDK21 and can allow unauthenticated arbitrary code execution through improper authorization and insufficient input validation.
Defused reported that CVE-2026-58231 was being targeted in the wild, with first exploitation attempts hitting its honeypots three days after SAP's patch release. SAP had not yet marked the vulnerability as actively exploited in its advisory.
SAP released patches for the maximum-severity SAP Commerce Cloud vulnerability CVE-2026-58231 and, in its August 2026 security update, also fixed CVE-2026-44772, CVE-2026-34265, and CVE-2026-44758. SAP and Onapsis urged customers to upgrade and redeploy fixed versions, with IP filtering suggested as a temporary mitigation for the Commerce Cloud issue.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
12 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcemkd-cirt.mk
Open sourcesecurityweek.com
Open sourceheise.de
Open sourcebleepingcomputer.com
Open sourcesocradar.io
Open sourcethehackernews.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.