CRITICAL: SAP Commerce Cloud CVE-2026-58231 Exploited Days After Patch
SAP shipped a CVSS 10.0 remote code execution fix for Commerce Cloud on August 11 and attackers were hitting honeypots with it three days later, despite no public proof of concept. CVE-2026-58231 lets an unauthenticated attacker run code through the Data Hub Adapter, and the fix only takes effect after a full rebuild and redeploy.