INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

| 2026-08-15 08:38 CRITICAL HIGH EXPLOITED VULNERABILITY
Executive Summary
AI-generated
The SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, has been exploited in the wild just days after a patch was released. This critical security flaw is rated 10.0 on the CVSS scoring system and allows for arbitrary code execution and compromise of internal components. Prior flaws impacting SAP products, including NetWeaver, have also been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx. The vulnerability has no public proof of concept and is not known to be exploited, but threat intelligence company Defused Cyber says it could permit arbitrary code execution and compromise internal components. Successful exploitation efforts have been detected on August 14 from a lone IP address located in the U.S., with two attempts already seen since April 2025.
Technical Mitigations AI-generated
* Configure an IP Filter Set in SAP Commerce Cloud to restrict access to the vulnerable endpoint and reduce exposure to potential attackers. * Ensure that all instances of SAP Commerce Cloud are patched to the fixed Commerce Cloud release levels referenced in the advisory, and re-build or redeploy the updated SAP Commerce Cloud version as soon as possible. * Implement a secure coding practice for input validation and authorization checks to prevent exploitation of this vulnerability. * Monitor system logs and network traffic for signs of unauthorized access or activity related to CVE-2026-58231, and take prompt action if any suspicious activity is detected.
Technical Observables Login Required
Indicators of Compromise (IoCs) Protected

Raw threat telemetry, malicious IP addresses, file hashes, and direct VirusTotal correlation are restricted to authenticated users.

hxxp://••••••••••••••••••••
me•••••.com
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
CVE-2026-44761CVE-2026-44761 CVE-2025-31324CVE-2025-31324 CVE-2026-44758CVE-2026-44758 CVE-2026-34265CVE-2026-34265 CVE-2026-58231CVE-2026-58231 CVE-2026-44772CVE-2026-44772 CVE-2026-34263CVE-2026-34263 CVE-2026-22732CVE-2026-22732
Target & Sectors
DACH DACH NORTH_AMERICA NORTH_AMERICA retailretail technologytechnology
Incident Timeline
‎November 2021
Threat actors used a known exploited vulnerability in SAP Commerce Cloud to target the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
tactic Ransomware
attribution Known Exploited
tactic T1588.006 - Vulnerabilities
general_metric 14 SAP vulnerabilities
‎April 2025
Threat actors exploited SAP NetWeaver CVE-2026-58231 to deploy a backdoor called Auto-Color in an attack targeting a U.S.-based chemicals company.
organisation SAP NetWeaver
organisation Auto-Color
‎fiscal year 2025
Threat actors exploited CVE-2026-58231 in SAP Commerce Cloud targeting 99 of the 100 largest companies worldwide.
target_region Germany
general_metric 99 corporation
general_metric 100 largest companies
financial €36 revenues
‎July 2026
SAP fixed 16 vulnerabilities in its July 2026 Security Patch package and 30 more vulnerabilities in June, May, and July.
organisation SAP Commerce Cloud
vulnerability CVE-2026-44761
vulnerability CVE-2026-22732
vulnerability CVE-2026-34263
organisation Commerce
general_metric 16 vulnerabilities
general_metric 30 more vulnerabilities
‎Aug 12, 2026
Threat actors exploited CVE-2026-58231 in the wild on August 12, 2026.
‎August 14
Threat actors used a known vulnerability in SAP Commerce Cloud CVE-2026-58231 to target the affected system.
vulnerability CVE-2026-58231
organisation Update
organisation KEVIntel
organisation IP
‎2026/08/14
Threat actors used a known vulnerability in SAP Commerce Cloud to target the affected software.
vulnerability CVE-2026-58231
organisation Defused
‎Aug 15, 2026
Threat actors exploited CVE-2026-58231 in the wild against SAP Commerce Cloud.
‎2026/08/15
Threat actors exploited a maximum-severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231.
organisation SAP
organisation NetWeaver
organisation APT
organisation SAP Commerce
organisation SAP Commerce Cloud
organisation CVSS
infrastructure 10.0
organisation Data Hub Adapter
organisation CVE
organisation IP
infrastructure 4,200 IP addresses
organisation Vulnerability / Cloud Security
organisation Commerce
organisation The Blue Report 2026
organisation SecurityAffairs
organisation BleepingComputer
organisation SAP’s
organisation Socket
organisation CVE-2026
organisation CVE-2026-44758
organisation SSTI
organisation CVE.org
organisation ABAP Platform
organisation DIAG
organisation XSL
‎2026/08/17
Threat actors used a vulnerability exploit in SAP Commerce Cloud to target the system, with an initial CVSS score of 10.0.
vulnerability CVE-2026-58231
vulnerability CVSS score of 10.0
‎August 2026
Threat actors exploited CVE-2026-58231 in the wild.
vulnerability CVE-2026-44772
infrastructure 9.9
general_metric 9.9 score
Tactical Metrics
Metrics
infrastructure
‎10.0
Software Version
Metrics
infrastructure
4,200
Ip Addresses
Metrics
financial
36,000,000,000
Revenues
Metrics
infrastructure
‎9.9
Software Version
Intelligence Sources