As per reports, researchers confirmed active exploitation attempts targeting a vulnerability in SAP Commerce Cloud, tracked as CVE-2026-58231.
Following are the details:
• An unauthenticated remote attacker can abuse a default authentication client and send specially crafted input without requiring existing privileges or user interaction.
• Successful exploitation allows arbitrary code execution and compromise of internal components, presenting direct risks to confidentiality, integrity, and availability.
• Security intelligence provider KEVIntel confirmed observing exploitation activity.
