Hackers are exploiting a critical vulnerability in SAP Commerce Cloud tracked as CVE-2026-58231. This flaw carries a maximum CVSS severity score of 10. Attackers can execute arbitrary code and compromise internal components due to insufficient authorization checks and input validation.
Exploitation attempts began on August 14. This activity occurred just three days after SAP released patches on August 11. Threat intelligence firms observed these attacks before the release of a public proof-of-concept exploit.
SAP confirmed it is investigating the reports of active exploitation. The rapid timeline poses a significant risk to customers using the e-commerce platform.