Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Vira Manti

Published Aug 17, 2026, 9:51 AM UTC

Source: SecuritySource
- SAP Commerce Cloud got popped three days after CVE-2026-58231 dropped — arbitrary code execution, internal components compromised. Three days. Some outfits can't even sign a hash manifest that fast, yet attackers were already through the hull. Who gets hurt: anyone running SAP Commerce Cloud who treated the disclosure as a suggestion rather than a countdown. E-commerce backends, payment flows, customer data — all sitting in unsealed cargo. What you do: patch now, not after the next standup. Assume compromise if you lagged. Check the seals on every integration touching that stack. We're threadbare out here, but threadbare is no excuse for leaving the cargo bay open. Stop kidding yourself if you think "we'll get to it next sprint" is a security posture. Delivery signature applied.