Security News

SAP Commerce Cloud Under Attack Just Days After Critical Flaw Disclosed

Security Week · 17 Aug 2026
Key Takeaway If you or your vendors use SAP Commerce Cloud, apply the latest security patches immediately and check with your IT provider whether your systems are affected.

A newly disclosed vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231, is already being exploited in the wild—just three days after details became public. The flaw allows attackers to execute arbitrary code and compromise internal system components, giving them a serious foothold within affected environments.

While SAP Commerce Cloud is primarily used by larger enterprises, many Australian small and medium businesses rely on it indirectly through e-commerce platforms, integrations, or third-party vendors who manage their online storefronts. Rapid exploitation of newly disclosed vulnerabilities like this highlights how little time businesses have to patch before attackers move in, and underscores the growing trend of threat actors weaponising flaws almost immediately after they're made public.

Organisations using SAP Commerce Cloud, or working with vendors who do, should confirm patch status urgently and review system logs for signs of compromise. Even businesses without direct exposure should take this as a reminder that speed of response to security disclosures is now a critical part of basic cyber hygiene.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.