Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4358 articles · 196331 vulns · 36/41 feeds (7d)
← Back to list
10.0
CVE-2026-58231KEVEXPLOITED
sap · sap commerce cloud (data hub adapter)

Improper Authorization in SAP Commerce Cloud (Data Hub Adapter)

Description

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

Affected Products

VendorProductVersions
sapsap commerce cloud (data hub adapter)COM_CLOUD 2211, 2211-JDK21

References

  • https://me.sap.com/notes/3771065
  • https://url.sap/sapsecuritypatchday

Related News (12 articles)

Tier D
SecurityWeek6d ago
Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure
→ No new info (linked only)
Tier D
Heise Security7d ago
Angriffe auf SAP-Commerce-Cloud-Lücke beobachtet
→ No new info (linked only)
Tier B
CERT-FR7d ago
Bulletin d'actualité CERTFR-2026-ACT-035 (17 août 2026)
→ No new info (linked only)
Tier E
Reddit r/cybersecurity8d ago
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
→ No new info (linked only)
Tier D
The Hacker News8d ago
SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch
→ No new info (linked only)
Tier D
BleepingComputer9d ago
Max severity SAP Commerce Cloud flaw now targeted in attacks
→ No new info (linked only)
Tier D
The Hacker News11d ago
SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
→ No new info (linked only)
Tier D
CSO Online12d ago
Patch Tuesday August 2026: A zero-day WinSock driver hole under exploit, and a maximum severity SAP vulnerability
→ No new info (linked only)
Tier D
SecurityWeek12d ago
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
→ No new info (linked only)
Tier D
Heise Security12d ago
Patchday: SAP Commerce Cloud komplett kompromittierbar
→ No new info (linked only)
Tier C
VulDB12d ago
CVE-2026-58231 | SAP Commerce Cloud 2211-JDK21/COM_CLOUD 2211 improper authentication
→ No new info (linked only)
Tier B
CERT-FR13d ago
Multiples vulnérabilités dans les produits SAP (11 août 2026)
→ No new info (linked only)
CVSS 3.110.0 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CISA KEV✅ Yes
Actively exploited✅ Yes
CWECWE-94
PublishedAug 11, 2026
Trending Score56
Source articles12
Independent8
Info Completeness0/14
Missing: cve_id, title, description, vendor, product, versions, cvss, epss, cwe, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-34265
Memory Corruption vulnerability in Application Server ABAP for SAP NetWeaver and ABAP Platform
Trending: 17
CRITICALCVE-2026-44758
Code Injection vulnerability in Manufacturing Integration and Intelligence
Trending: 14
HIGHCVE-2026-44764
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 13
HIGHCVE-2026-44765
Missing Authorization Check in SAP Manufacturing Integration and Intelligence
Trending: 13
HIGHCVE-2026-58243
Privilege Escalation vulnerability in SAP ABAP Developer Tools
Trending: 11

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 11, 2026
Added to CISA KEV
Aug 11, 2026
Discovered by ZDM
Aug 11, 2026
Actively Exploited
Aug 12, 2026