Exploitation attempts are targeting SAP Commerce Cloud vulnerability CVE-2026-58231, a maximum-severity flaw that can allow unauthenticated remote code execution. Threat intelligence firm Defused reported on August 14 that attempts were reaching its honeypots three days after SAP released a patch. SAP told BleepingComputer that it was aware of the report and investigating, while urging customers and partners to patch immediately.

SAP disclosed CVE-2026-58231 during its August 11 Security Patch Day. The issue affects the Data Hub Adapter in SAP Commerce Cloud versions COM_CLOUD 2211 and 2211-JDK21, according to the vendor bulletin. Commerce Cloud, formerly known as SAP Hybris, supports online stores and other enterprise commerce operations, making exposed deployments a potentially valuable target.

SAP classifies the flaw as an improper authorization weakness. The NIST National Vulnerability Database says an attacker can abuse a default authentication client and send specially crafted input to functions that do not perform sufficient validation. Successful exploitation could execute arbitrary code and compromise internal application components, affecting confidentiality, integrity and availability.

SAP assigned the vulnerability a CVSS score of 10.0. The published vector indicates a network-based attack with low complexity, no required privileges and no user interaction. Defused said no public proof-of-concept was known when it detected the attempts. No victim count, successful compromise evidence or attack indicators were disclosed in the report, so the observed honeypot traffic should not be treated as proof of widespread compromise.

Shadowserver data cited by BleepingComputer showed more than 4,200 IP addresses with an SAP Commerce Cloud fingerprint, concentrated mainly in Europe and North America. The measurement does not establish how many systems are vulnerable: the set can include patched deployments and honeypots. Administrators should therefore identify affected Data Hub Adapter installations directly instead of inferring exposure from internet scan totals.

SAP customers should apply Security Note 3771065 and confirm that corrected applications are deployed across all affected environments. Defenders should reduce unnecessary internet exposure, review application and network logs for unusual requests or unexpected code execution, and preserve evidence from systems showing suspicious activity. Until SAP completes its investigation, response decisions should rely on verified local telemetry and the vendor advisory rather than unconfirmed exploitation claims.