SAP Commerce Cloud CVSS 10.0: three days to exploit
CVE-2026-58231 is an unauthenticated RCE in SAP Commerce Cloud's Data Hub Adapter. SAP patched August 11. Honeypots saw exploitation August 14.
SAP shipped a fix for CVE-2026-58231 on August 11. Three days later it was being exploited. The flaw is a CVSS 10.0 unauthenticated remote code execution bug in SAP Commerce Cloud — the platform formerly called Hybris, still running a large share of enterprise B2B and B2C storefronts. If you run it, your patch window closed while you were reading the advisory.
What actually happened
The bug lives in the Data Hub Adapter extension. It is an improper authorization weakness: the component ships a default authentication client that can be abused to reach functions the caller was never supposed to reach, and crafted input through those functions executes arbitrary code. No credentials. No user interaction. Low complexity. That combination is what gets you a 10.0.
SAP published the fix as Security Note 3771065 on its August 2026 Security Patch Day, August 11. Remediation means moving affected 2211 deployments to 2211.55, 2211-jdk21.17, or a later supported release — and redeploying, which is the step people skip.
On August 14, threat intelligence firm Defused reported exploitation attempts against the CVE hitting its honeypots, as BleepingComputer covered. Shadowserver tracks more than 4,200 internet-exposed instances with a SAP Commerce Cloud fingerprint, concentrated in Europe and North America. Nobody has published how many of those are patched.
Why this SAP Commerce Cloud flaw matters for your business
Three days is now the planning number. Patch Tuesday to weaponised exploit used to be measured in weeks. We watched the same compression on Adobe Commerce CVE-2026-71362 last week — patched August 11, WAF blocks the next day. If your change process needs a two-week approval cycle for a CVSS 10.0 in a public-facing storefront, the process is the vulnerability.
Check the running release, not the ticket. SAP Commerce Cloud deployments get patched by redeploying the application. A closed ticket that says "note applied" is not evidence. Pull the actual build version from the running environment and compare it to 2211.55. We have seen too many "patched" systems where the fix sat in a branch nobody promoted.
RCE means assume execution, not just exposure. If you were exposed and internet-facing, patching removes the door and nothing else. Look for new scheduled jobs, unexpected outbound connections from the app tier, modified extensions, and new admin users in the Backoffice. The audit trail is the deliverable, not the patch.
Ask who owns the Data Hub. Data Hub Adapter is integration plumbing — it usually got installed by whoever built your ERP or PIM sync, years ago, and has not been touched since. That is exactly the kind of component that stays exposed because nobody thinks of it as part of the store.
Key takeaways
- CVE-2026-58231 is a CVSS 10.0 improper-authorization flaw in the SAP Commerce Cloud Data Hub Adapter, allowing unauthenticated remote code execution
- SAP fixed it in Security Note 3771065 on its August 11, 2026 Patch Day; fixed releases are 2211.55, 2211-jdk21.17 or later
- Defused reported exploitation attempts against its honeypots on August 14 — three days after the patch
- Shadowserver counts 4,200+ internet-exposed SAP Commerce Cloud instances, mostly in Europe and North America
- Applying the note is not enough — you must redeploy and verify the running build version
- If you were exposed, hunt for post-exploitation artefacts: new jobs, new admin users, outbound connections from the app tier
If nobody can tell you what version your storefront is actually running, that is the finding. We build and maintain commerce systems where the deploy pipeline, the version, and the patch schedule are yours to see. See how we build commerce systems or get a straight read on your exposure.
Sources: BleepingComputer, The Hacker News.
- #cve-2026-58231
- #sap-commerce-cloud
- #ecommerce-security
- #patch-management
- #rce
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Stripe's PayPal bid advances: your processor may change hands
Stripe and Advent bid $53B for PayPal and talks are heating up. If both sit in your checkout, your payment redundancy just became one vendor.
Read itShopify's Shop app holiday push: whose customer is it?
Shopify is running its first long multiphase holiday campaign for the Shop app after native GMV grew over 70% in Q2. Here's the merchant-side read on that channel.
Read it