Threat actors have commenced active exploitation of a critical vulnerability in SAP Commerce Cloud, designated as CVE-2026-58231. This flaw, assigned the highest possible CVSS score of 10.0, allows unauthenticated attackers to execute arbitrary code remotely without user interaction or existing privileges.
SAP Commerce Cloud is a widely used platform supporting global digital storefronts and supply chain operations. A successful exploit of this vulnerability could grant attackers full administrative control over backend databases, transaction pipelines, and sensitive enterprise assets.
Defused, a cybersecurity monitoring organization, detected the initial exploitation attempts targeting exposed application endpoints on standard web port 443. Activity logs indicate that the attack traffic originated from hosting infrastructure associated with Charlotte Colocation Center (AS11402) in the United States, specifically from the IP address 216.249.99[.]43.
The observed activity suggests that opportunistic actors are systematically scanning internet-facing SAP deployments to identify vulnerable installations. The rapid emergence of in-the-wild exploitation, despite the absence of a public proof of concept, indicates that threat actors likely reverse-engineered the vendor patch immediately upon its release.
Enterprises operating complex SAP environments often face extended patch testing cycles, creating a window of opportunity for attackers. Threat actors routinely target enterprise commerce platforms to deploy web shells, exfiltrate customer payment information, and establish persistent footholds for broader corporate network intrusions.
Security teams managing SAP deployments must address this active threat with immediate urgency by applying the official vendor updates across all internet-facing and internal instances. Administrators should inspect ingress web server logs and web application firewalls for anomalous POST requests directed at administrative services from external hosts.
Organizations unable to apply the update immediately should consider placing exposed management interfaces behind a virtual private network and enforcing strict access control lists to reduce attack exposure.
This incident underscores the critical importance of timely patch management and proactive monitoring in safeguarding enterprise systems against emerging threats.