Skip to content

SAP Commerce Cloud: Active Attacks Exploiting Critical Security Vulnerability

In short: A critical security vulnerability in SAP Commerce Cloud is already being actively exploited in attacks; affected companies should patch immediately and check for compromise.

Attackers are currently actively compromising SAP Commerce Cloud instances via a critical security vulnerability. The corresponding attacks are already underway, so affected organizations should immediately check whether their systems are exposed.

According to the source, attackers are exploiting a critical security vulnerability in SAP Commerce Cloud to inject malicious code into affected instances and compromise the systems. The corresponding attacks are already taking place, meaning this is not a theoretical risk but actively exploited attack attempts.

For security leaders at companies using SAP Commerce Cloud, this creates an immediate need for action. E-commerce platforms like SAP Commerce Cloud often process customer data and payment information and are directly accessible from the internet, making them an attractive target for attackers. In addition to data exfiltration, a successful compromise can also lead to downtime in customer-facing operations and reputational damage.

CISOs should promptly check the patch status of their SAP Commerce Cloud environments, apply available security updates from SAP without delay, and examine the systems for indicators of prior compromise. Since, according to the source, active exploitation is already occurring, merely tracking patch cycles is not sufficient—additional monitoring and detection measures for the affected systems are advised until the patch status is fully confirmed.


Source: www.golem.de · Published August 17, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: