
A maximum-severity remote code execution vulnerability in SAP Commerce Cloud is being actively exploited in the wild — just three days after SAP released a patch. Threat intelligence firm Defused confirmed the attacks on Friday, reporting that exploitation attempts against CVE-2026-58231 were already hitting their honeypots.
SAP Commerce Cloud (formerly SAP Hybris) is the e-commerce platform behind the online stores of major global retailers and brands. The flaw is in its Data Hub Adapter extension: an unauthenticated attacker can send specially crafted input to certain functions that lack sufficient validation, abuse a default authentication client, and execute arbitrary code on the server — no credentials, no prior access needed. SAP rates it CVSS 10.0. Shadowserver tracks over 4,200 internet-exposed Commerce Cloud instances, the majority located in Europe and North America. There is no public proof-of-concept, but Defused’s honeypot data confirms weaponized exploitation has already begun.
How to check if you’re affected
Affected products are SAP Commerce Cloud deployments running the Data Hub Adapter extension that have not yet applied the July 2026 SAP Security Patch Package. Check your installed version and patch status in the SAP Support Portal. SAP has not yet updated its security advisory to flag the flaw as actively exploited, but Defused’s confirmation makes patching urgent regardless of the advisory status.
