Critical SAP Commerce Cloud Flaw Rated Maximum Severity — Patch Now
SAP has released patches for a critical security flaw affecting Commerce Cloud's Data Hub Adapter, tracked as CVE-2026-58231. The vulnerability has been given the highest possible severity score of 10.0 on the CVSS scale, meaning it poses an extreme risk if left unpatched.
The issue stems from insufficient authorization checks and input validation within the platform, which could allow an unauthenticated attacker to execute arbitrary code without needing valid credentials. This type of flaw is particularly dangerous because it removes the usual barrier of requiring stolen passwords or insider access, making exploitation easier for attackers.
Businesses using SAP Commerce Cloud, particularly those relying on the Data Hub Adapter for e-commerce or data integration, should treat this as an urgent priority. Given the maximum severity rating, security researchers and threat actors alike are likely to scrutinise this vulnerability closely, increasing the risk of exploitation attempts once details become more widely known.