Security Affairs
Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains|50,000 Stripe Secrets Leaked in Public Code|U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog|Hackers Expose Data of 1.2 Million Heights Finance Customers|Project noRecognition: Teaching AI to Fool Surveillance Cameras|GitLab Patches Critical Unauthenticated GraphQL Vulnerability|U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog|New Mirai-Based Evooo1Bot Botnet Targets Linux Devices|SafePal Says 39,798 Customers Hit by Data Breach|LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected|Invisible AI Prompts Trigger Court Sanctions|McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen|Microsoft Tracks MacSync Stealer by Its Behavior, Not Its Domains|50,000 Stripe Secrets Leaked in Public Code|U.S. CISA adds Apple macOS, Microsoft SharePoint, Broadcom VMware vCenter, and Microsoft IKE flaws to its Known Exploited Vulnerabilities catalog|Hackers Expose Data of 1.2 Million Heights Finance Customers|Project noRecognition: Teaching AI to Fool Surveillance Cameras|GitLab Patches Critical Unauthenticated GraphQL Vulnerability|U.S. CISA adds a Ray-Project Ray flaw to its Known Exploited Vulnerabilities catalog|New Mirai-Based Evooo1Bot Botnet Targets Linux Devices|SafePal Says 39,798 Customers Hit by Data Breach|LiteLLM Supply-Chain Attack – Technology, Banking and Healthcare the Most Affected|Invisible AI Prompts Trigger Court Sanctions|McDonald’s Employee Data Appears in Leak, Seller Claims 1.7M Records Stolen|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

SAP Commerce Cloud CVE-2026-58231 Exploited in the Wild

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch. A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation. […]

SAP Commerce Cloud CVE-2026-58231

Attackers are actively exploiting a maximum severity SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231, just days after SAP released a patch.

A critical SAP Commerce Cloud vulnerability, tracked as CVE-2026-58231 (CVSS score of 10.0), is under active exploitation just days after SAP released a patch. The flaw stems from insufficient authorization checks and input validation.

“SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation.” reads the advisory. “Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.”

An unauthenticated attacker can abuse a default authentication client and send crafted input to vulnerable functions, potentially achieving arbitrary code execution and compromising internal components.

Researchers at Defused Cyber observed exploitation attempts against honeypots only three days after the patch was released. The researchers pointed out that this vulnerability has no public PoC and had not been known to be exploited prior to their discovery.

The attackers behind the current exploitation remain unknown. However, previous critical SAP flaws have been exploited by China-linked APT groups, including UNC5221 and UNC5174, and ransomware gangs.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, SAP Commerce Cloud)