Threat Intelligence

Critical SAP Commerce Cloud Flaw Rated Maximum Severity — Patch Now

The Hacker News · 12 Aug 2026
Key Takeaway If your business uses SAP Commerce Cloud, apply the latest security patches immediately to close this maximum-severity vulnerability before attackers can exploit it.

SAP has released patches for a critical security flaw affecting Commerce Cloud's Data Hub Adapter, tracked as CVE-2026-58231. The vulnerability has been given the highest possible severity score of 10.0 on the CVSS scale, meaning it poses an extreme risk if left unpatched.

The issue stems from insufficient authorization checks and input validation within the platform, which could allow an unauthenticated attacker to execute arbitrary code without needing valid credentials. This type of flaw is particularly dangerous because it removes the usual barrier of requiring stolen passwords or insider access, making exploitation easier for attackers.

Businesses using SAP Commerce Cloud, particularly those relying on the Data Hub Adapter for e-commerce or data integration, should treat this as an urgent priority. Given the maximum severity rating, security researchers and threat actors alike are likely to scrutinise this vulnerability closely, increasing the risk of exploitation attempts once details become more widely known.

SAP vulnerability patch management e-commerce security enterprise software

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.