Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Trump Puts on a Midterms Show for an Audience That’s Already Sold

    October 2, 2026

    OpenAI’s Dot agent can help you work and order dinner

    October 2, 2026

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    October 2, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Trump Puts on a Midterms Show for an Audience That’s Already Sold
    • OpenAI’s Dot agent can help you work and order dinner
    • Is It Fair to Blame ‘Rogue’ AI for Security Failures?
    • This AI Is Already Fooling People on Video Calls Into Thinking Its Human, Company Says
    • Creatine may help build muscle even without exercise, researchers find
    • Permafrost, wetland, wildfire and freshwater emissions could amplify climate change by up to 30%, study finds
    • The Guardian view on Barack Obama’s new podcast: all the president’s books | Editorial
    • Woman at centre of Cornell rape inquiry ‘failed’ by officials, says New York governor
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Friday, October 2
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 17, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers started exploiting a critical vulnerability in SAP Commerce Cloud just three days after its public disclosure, according to threat intelligence organizations.

    The vulnerability is tracked as CVE-2026-58231 and is described as an issue involving insufficient authorization checks and input validation. 

    An attacker can exploit the vulnerability, which has a CVSS score of 10, to execute arbitrary code and compromise internal components.

    SAP announced patches for CVE-2026-58231 on August 11 and Defused reported that its honeypots had started seeing exploitation attempts on August 14. The security firm noted that there had been no public PoC exploit and no prior reports of in-the-wild exploitation.

    KEVIntel, which uses proprietary sensors and private honeypots to observe exploitation attempts, independently confirmed seeing attacks.

    The organization noted on August 15 that a PoC exploit has become available. 

    Advertisement. Scroll to continue reading.

    CISA’s Known Exploited Vulnerabilities (KEV) catalog currently includes 14 SAP product flaws, but only one of them, CVE-2019-0344, affects Commerce Cloud. The security hole was added to the KEV list in 2024. 

    CISA has yet to add CVE-2026-58231 to its catalog. 

    Related: Adobe Commerce Bug Targeted Immediately After Disclosure

    Related: Fortune 500 Companies Hit in Azure Data Theft Campaign

    Related: Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    Related: Hackers Exploiting Unpatched GeoServer Zero-Day

    cloud commerce critical days Disclosure Exploited SAP Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

    SWIFT Banking & Government Middleware Enables RCE

    In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

    US sanctions Tren de Aragua gang members in ATM hacks crackdown

    Vulnerability Backlogs Are an Ownership Problem

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Trump Puts on a Midterms Show for an Audience That’s Already Sold

    October 2, 2026

    OpenAI’s Dot agent can help you work and order dinner

    October 2, 2026

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    October 2, 2026

    This AI Is Already Fooling People on Video Calls Into Thinking Its Human, Company Says

    October 2, 2026
    Latest Posts

    Lime bikes hurtling around the city: is this the revenge of a priced-out generation? | Andy Beckett

    August 8, 2026

    Clarity Act Delayed Until September, Trump Praises Bitcoin

    August 8, 2026

    North Carolina Ports confirms cyberattack disrupting operations

    August 8, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Trump Puts on a Midterms Show for an Audience That’s Already Sold

    October 2, 2026

    OpenAI’s Dot agent can help you work and order dinner

    October 2, 2026

    Is It Fair to Blame ‘Rogue’ AI for Security Failures?

    October 2, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.