Skip to content

Critical SAP Commerce Cloud vulnerability with CVSS 10.0 already being actively exploited

Bottom line: A remote code execution flaw in SAP Commerce Cloud rated CVSS 10.0 is already being actively exploited just three days after the patch was released.

Just three days after a patch was released for a remote code execution vulnerability in SAP Commerce Cloud, threat intelligence company Defused is already registering initial exploitation attempts in the wild. The vulnerability was rated with the maximum CVSS score of 10.0.

SAP released a security patch three days ago for a critical remote code execution vulnerability in SAP Commerce Cloud. The flaw received the highest possible CVSS rating of 10.0. According to Defused, a company specializing in threat intelligence, active attack attempts targeting this vulnerability are already being observed. Further technical details on the specific exploitation method are not available from the original source.

For companies operating SAP Commerce Cloud as an e-commerce platform, there is an immediate need for action given the maximum severity of the flaw and the attacks that began shortly after the patch was released. Remote code execution vulnerabilities of this category typically allow attackers to execute arbitrary code on the affected systems, which, in the event of successful compromise, can have far-reaching consequences for the confidentiality, integrity, and availability of the commerce platform as well as connected customer data.

CISOs should immediately check whether SAP Commerce Cloud instances are in use within their own organization and prioritize verifying the patch status. Since exploitation has already begun before widespread patch adoption, a short-term review of systems for indicators of compromise is also advisable, along with close coordination with the SAP Basis team to expedite deployment of the security update. Until systems are fully patched, compensating measures such as tighter network segmentation and enhanced monitoring of the affected systems can help reduce the risk.


Source: www.bleepingcomputer.com · Published August 14, 2026
Lumi AI News — AI-assisted curation pursuant to Art. 50 EU AI Act. Paraphrasing and classification by Lumi News Pipeline v1.8.3.

Share on: