Apply the security update released by SAP to address CVE-2026-58231 immediately. Prioritize patching all SAP Commerce Cloud instances, especially those exposed to the internet. Monitor for further exploitation activity and review authentication client configurations.
Quick answers
What is CVE-2026-58231?
Apply the security update released by SAP to address CVE-2026-58231 immediately. Prioritize patching all SAP Commerce Cloud instances, especially those exposed to the internet. Monitor for further exploitation activity and review authentication client configurations.
How severe is CVE-2026-58231?
critical, CVSS 10
Is CVE-2026-58231 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-58231 be mitigated?
Apply the security update released by SAP to address CVE-2026-58231 immediately. Prioritize patching all SAP Commerce Cloud instances, especially those exposed to the internet. Monitor for further exploitation activity and review authentication client configurations.
CVSS
10
Vendor
SAP
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
SAP Commerce Cloud
Mitigation
Apply the security update released by SAP to address CVE-2026-58231 immediately. Prioritize patching all SAP Commerce Cloud instances, especially those exposed to the internet. Monitor for further exploitation activity and review authentication client configurations.
A maximum-severity vulnerability in SAP Commerce Cloud is being actively exploited in the wild days after SAP released a security update. Tracked as CVE-2026-58231, the flaw carries a CVSS score of 10.0 and involves insufficient authorization checks and input validation that could allow unauthenticated attackers to abuse a default authentication client.