Threat Intelligence

Critical SAP Commerce Cloud Flaw Under Active Attack — Patch Immediately

The Hacker News · 15 Aug 2026
Key Takeaway If your business uses SAP Commerce Cloud, apply the latest security patch immediately and check systems for signs of compromise.

A newly disclosed security flaw in SAP Commerce Cloud, tracked as CVE-2026-58231, has received the highest possible severity score of 10.0 out of 10. The vulnerability stems from insufficient authorization checks and input validation, allowing an unauthenticated attacker to abuse a default authentication client to submit unauthorized requests to the system.

What makes this especially concerning is the speed of exploitation. Security researchers have observed active attack attempts against this vulnerability within days of a patch being made available, meaning attackers moved quickly to target organisations that had not yet updated their systems. This pattern is common with high-severity flaws — once details become public, cybercriminals race to exploit unpatched systems before businesses catch up.

Any Australian business using SAP Commerce Cloud for e-commerce or customer-facing platforms should treat this as an urgent priority. Because the flaw does not require authentication to exploit, attackers can potentially access systems without needing stolen credentials, making it a particularly attractive target for opportunistic and organised threat actors alike.

SAP vulnerability patch management e-commerce security critical CVE

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.