ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

SAP Commerce Cloud CVE-2026-58231 Targeted in Exploitation Attempts Days After Patch

criticalExploit / PoC exploited in the wildimportance 80CVE-2026-58231CVE-2025-31324
AI summary · glm-5.3-flash

A maximum-severity (CVSS 10.0) unauthenticated RCE flaw in SAP Commerce Cloud, CVE-2026-58231, is under active exploitation days after patching.

CVE-2026-58231, rated 10.0 on CVSS, stems from insufficient authorization checks and input validation in SAP Commerce Cloud, enabling unauthenticated arbitrary code execution. Defused Cyber's honeypots detected exploitation attempts three days after the patch, and KEVIntel independently confirmed two attempts on August 14 from a US IP address. Onapsis urges customers to patch and rebuild, with an IP Filter Set offered as a temporary workaround. No actor attribution yet, though prior SAP NetWeaver flaw CVE-2025-31324 was exploited by China-nexus and criminal groups.

  • CVE-2026-58231 (CVSS 10.0) allows unauthenticated RCE and compromise of internal components
  • Honeypot detections began three days post-patch; KEVIntel saw attempts August 14
  • Fixed builds must be patched, rebuilt, and redeployed per SAP guidance
  • IP Filter Set configuration available as temporary mitigation

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-31324
Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer

CVE-2025-31324 is a critical (CVSS 9.8) unrestricted file upload flaw (CWE-434) in the Visual Composer Metadata Uploader component of SAP NetWeaver, which lacks proper authorization. An unauthenticated attacker can send crafted upload requests over the network to the Metadata Uploader endpoint and plant malicious executable binaries, such as webshells, on the host. Executing the uploaded files yields remote code execution with full impact on confidentiality, integrity, and availability, enabling system compromise, lateral movement, and ransomware deployment. Any organization running the affected SAP NetWeaver component is at risk, with the greatest exposure for instances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-04-29, a public PoC exists, and researchers and media report active attacks, including by Chinese-linked actors deploying Golang-based implants on Linux systems and known ransomware use, often chained with CVE-2025-42999.

Do: Apply SAP's patch for CVE-2025-31324 (released in the April 2025 security updates) and follow the vendor mitigation instructions per CISA KEV/BOD 22-01 requirements. As interim mitigation, restrict or disable the Visual Composer Metadata Uploader endpoint and ensure it is not reachable from the internet; also patch the related CVE-2025-42999 since the flaws are being chained. Check affected hosts for uploaded webshells, Golang-based implants, and signs of ransomware activity.

9.8100% KEV ransomware PoC
  • sap netweaver
largetens of thousands of enterprise deployments worldwide, with several thousand instances directly internet-exposed
CVE-2026-58231
SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking s

SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation. Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application.

NVD description · AI analysis pending
10.02%
Full article345 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 15, 2026Vulnerability / Cloud Security

A maximum-severity security vulnerability impacting SAP Commerce Cloud is witnessing active exploitation efforts.

The vulnerability, tracked as CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It relates to an instance of insufficient authorization checks and input validation.

"SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to certain functions lacking sufficient validation," per CVE.org.

"Successful exploitation could enable arbitrary code execution and compromise internal components, resulting in high impact on confidentiality, integrity, and availability of the application."

According to Defused Cyber, exploitation attempts against CVE-2026-58231 began to hit its honeypot systems merely three days after the release of the patch.

"This vulnerability has no public PoC and is not known to be exploited," the threat intelligence company said in an X post shared on Friday.

SAP security company Onapsis noted earlier this week that successful exploitation of CVE-2026-58231 could permit arbitrary code execution and compromise internal components.

"Customers must patch to the fixed Commerce Cloud release levels referenced in the note and re-build/re-deploy the updated SAP Commerce Cloud version," it said. "As a temporary workaround, customers can reduce their exposure by configuring an IP Filter Set in SAP Commerce Cloud to restrict access to the vulnerable endpoint."

There are currently no details available on who is behind the exploitation efforts targeting the flaw. However, prior flaws (CVE-2025-31324) impacting SAP products, including NetWeaver, have been weaponized by China-nexus espionage clusters like UNC5221, UNC5174, and CL-STA-0048, as well as cybercrime groups such as BianLian and RansomExx.

In April 2025, unknown threat actors were also observed exploiting the same critical SAP NetWeaver vulnerability to deploy a backdoor called Auto-Color in an attack aimed at a U.S.-based chemicals company.

Update

KEVIntel has also independently confirmed seeing exploitation efforts against CVE-2026-58231, with two attempts detected on August 14 from a lone IP address located in the U.S.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html