Home / Aug 18, 2026 / Story
0
#2 SecurityWeek general August 17, 2026 at 08:13 UTC

Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

By Eduard Kovacs

AI Summary

CVE-2026-58231, a maximum-severity (CVSS 10.0) insufficient authorization flaw in SAP Commerce Cloud, was exploited in the wild just three days after its public disclosure. The vulnerability allows unauthenticated attackers to abuse a default authentication client for arbitrary code execution, underscoring the critical need for rapid patch deployment on internet-facing SAP deployments.

Relevance score: 86.0/100

# More from August 18