Particle.news

Critical SAP Commerce Cloud Flaw Targeted in Early Exploit Attempts

The unauthenticated bug lets attackers run code on exposed backends, creating urgent need for operators to install SAP’s patch.

Overview

  • SAP released Security Note 3771065 fixing CVE-2026-58231 on August 11, 2026, which patches an improper-authorization flaw in the Commerce Cloud Data Hub Adapter that can lead to unauthenticated remote code execution.
  • Security researchers at Defused observed exploit attempts hitting honeypots three days after the patch, showing attackers probed exposed backends rapidly after the fix was published.
  • Public evidence does not yet show a working proof-of-concept or confirmed post-exploitation compromises, so HTTP probe traffic should be treated as attempts until JVM processes, shells, files, or callbacks prove RCE.
  • Administrators are urged to apply Security Note 3771065, rebuild and redeploy fixed builds, restrict Data Hub endpoints with IP Filter Sets, and remove direct internet access to the Data Hub Adapter to contain exposure.
  • Shadowserver reports 4,200+ IPs with Commerce Cloud fingerprints but that does not equal unpatched systems, and the incident raises urgency because SAP components have been attractive targets in past supply-chain and ransomware incidents.