Close Menu
NCIJ Network NCIJ Network
    What's Hot

    The Guardian view on a vibrant summer for British athletics: inspiring a generation | Editorial

    August 17, 2026

    After the Earthquakes – The New York Times

    August 17, 2026

    The island, the letters, the loos

    August 17, 2026
    Facebook X (Twitter) Instagram
    Trending
    • The Guardian view on a vibrant summer for British athletics: inspiring a generation | Editorial
    • After the Earthquakes – The New York Times
    • The island, the letters, the loos
    • UK government ‘irresponsible’ for not publishing emergency drought plans | Drought
    • This R-Rated Film Studio Wants to Be the HBO of AI
    • MiniMax Releases MiniMax-Music3: An Open-Weights Music Model Generating Complete Five-Minute Songs From Lyrics and a Structured Caption
    • Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
    • Bybit Brazil deadline: Liquidations start Sept. 21
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Monday, August 17
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 17, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Hackers started exploiting a critical vulnerability in SAP Commerce Cloud just three days after its public disclosure, according to threat intelligence organizations.

    The vulnerability is tracked as CVE-2026-58231 and is described as an issue involving insufficient authorization checks and input validation. 

    An attacker can exploit the vulnerability, which has a CVSS score of 10, to execute arbitrary code and compromise internal components.

    SAP announced patches for CVE-2026-58231 on August 11 and Defused reported that its honeypots had started seeing exploitation attempts on August 14. The security firm noted that there had been no public PoC exploit and no prior reports of in-the-wild exploitation.

    KEVIntel, which uses proprietary sensors and private honeypots to observe exploitation attempts, independently confirmed seeing attacks.

    The organization noted on August 15 that a PoC exploit has become available. 

    Advertisement. Scroll to continue reading.

    CISA’s Known Exploited Vulnerabilities (KEV) catalog currently includes 14 SAP product flaws, but only one of them, CVE-2019-0344, affects Commerce Cloud. The security hole was added to the KEV list in 2024. 

    CISA has yet to add CVE-2026-58231 to its catalog. 

    Related: Adobe Commerce Bug Targeted Immediately After Disclosure

    Related: Fortune 500 Companies Hit in Azure Data Theft Campaign

    Related: Critical Flaws Discovered in Belgian eID Software Used by 2 Million People

    Related: Hackers Exploiting Unpatched GeoServer Zero-Day

    cloud commerce critical days Disclosure Exploited SAP Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    40,000 Impacted by SafePal Data Breach

    Certighost and the Privilege Hiding in Your Certificate Authority

    Why data quality dictates security operations success

    680,000 Impacted by French Tax Authority Data Breach

    Microsoft confirms GitHub is down worldwide

    ⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    The Guardian view on a vibrant summer for British athletics: inspiring a generation | Editorial

    August 17, 2026

    After the Earthquakes – The New York Times

    August 17, 2026

    The island, the letters, the loos

    August 17, 2026

    UK government ‘irresponsible’ for not publishing emergency drought plans | Drought

    August 17, 2026
    Latest Posts

    Wisconsin’s Democratic primary for governor: a look at the 5 remaining

    July 27, 2026

    UK CO2 storage project that will reuse existing infrastructure secures lease

    July 27, 2026

    Bangladesh shipbreakers push back against stricter environmental standards

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    The Guardian view on a vibrant summer for British athletics: inspiring a generation | Editorial

    August 17, 2026

    After the Earthquakes – The New York Times

    August 17, 2026

    The island, the letters, the loos

    August 17, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.