Home / Aug 19, 2026 / Story
0
#7 The Hacker News general August 15, 2026 at 08:38 UTC

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

By [email protected] (The Hacker News)

AI Summary

CVE-2026-58231, a CVSS 10.0 maximum-severity authentication bypass in SAP Commerce Cloud, is being actively exploited within days of its patch release, allowing unauthenticated attackers to abuse a default authentication client to submit unauthorized requests. The vulnerability stems from insufficient authorization checks and input validation. SAP Commerce Cloud administrators must apply the patch immediately, as exploit attempts are already confirmed in the wild.

Relevance score: 82.0/100

# More from August 19