#7
The Hacker News
general
August 15, 2026 at 08:38 UTC
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
By [email protected] (The Hacker News)
AI Summary
CVE-2026-58231, a CVSS 10.0 maximum-severity authentication bypass in SAP Commerce Cloud, is being actively exploited within days of its patch release, allowing unauthenticated attackers to abuse a default authentication client to submit unauthorized requests. The vulnerability stems from insufficient authorization checks and input validation. SAP Commerce Cloud administrators must apply the patch immediately, as exploit attempts are already confirmed in the wild.
Relevance score: 82.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →