SAP Commerce Cloud CVE-2026-58231 Critical Flaw Exploited in the Wild Just Three Days After Patch
SAP Commerce Cloud has been struck by a maximum-severity vulnerability, CVE-2026-58231, rated CVSS 10.0. The flaw permits unauthenticated remote code execution and was actively exploited in the wild only three days after the vendor released patches.
Security researchers first published exploitation traffic on 14 August, catching many organizations still digesting the August patch bulletin. SAP assigned the issue its highest priority rating, HotNews, while firms such as Onapsis placed it at the top of their remediation lists for the month.
Where the flaw resides
The vulnerability affects the Data Hub Adapter component responsible for exchanging and importing data between SAP Commerce Cloud and external systems. Attackers abuse a default authentication client that possesses excessive privileges and lacks proper input validation, effectively granting a universal access token to any reachable endpoint.
No credentials or user interaction are required; a single HTTP request is sufficient to achieve arbitrary code execution and full compromise of the application and its connected components.
Why the platform is a high-value target
SAP Commerce Cloud, formerly known as SAP Hybris, serves as the online storefront and B2B transaction layer for numerous global retailers and manufacturers. It is deeply integrated with ERP, CRM, inventory, payment, and fulfillment systems, meaning a breach can expose an entire business chain.
Scanning data from Shadowserver shows more than 4,200 internet-reachable instances worldwide, concentrated in Europe and North America, underscoring the broad attack surface.
Rapid weaponization driven by automation
Security teams observed the first exploitation attempts on 14 August, three days after the 11 August patch release. Analysts attribute the speed to automated and AI-assisted reverse engineering that quickly identifies patch differences and constructs working exploits.
This compressed timeline renders traditional quarterly patching cycles obsolete and forces organizations to treat such issues as immediate emergency events.
Immediate mitigation steps
- Upgrade to SAP Commerce Cloud 2211.55, 2211-jdk21.17 or later versions listed in security note 3771065.
- Verify that production systems are actually running the updated releases.
- Apply IP Filter Sets to restrict Data Hub Adapter endpoints to trusted sources only.
- Map all backend integrations, service accounts, and data flows to understand potential blast radius before an incident occurs.
Related articles
WordPress Login Page Exposed to Critical XSS2Shell Flaw CVE-2026-64638: Over 11,000 Sites Attacked Across 67 Countries
WordPress core login page vulnerability CVE-2026-64638 enables unauthenticated attackers to trigger reflected XSS that can escalate to full server compromise. The flaw stems from mismatched HTML sanitization between two filtering layers on the wp-login.php page, allowing malicious payloads to execute in the site origin. Imperva observed automated campaigns hitting more than 11,000 sites with hundreds of thousands of requests, predominantly affecting U.S. targets in gaming, education, and finance sectors. Successful exploitation chains the XSS into WordPress REST API and application password creation when an administrator is logged in, ultimately allowing malicious plugin uploads. Official patches are available in WordPress 7.0.3 and backported releases down to 4.7; administrators are urged to verify versions, audit user accounts, and inspect plugin directories immediately.
WireGuard Kernel Module Silently Overwrites AllowedIPs in Trie, Breaking Peer Routing Without Errors
The WireGuard kernel module stores AllowedIPs in a single prefix trie per device rather than per peer, causing exact-match insertions of identical CIDR prefixes to reassign nodes and remove them from the previous peer's list. This behavior silently drops routing for affected peers while handshakes and inbound traffic continue, leading to one-way connectivity failures and frame errors. The issue affects road-warrior setups using 0.0.0.0/0, mesh networks, Kubernetes CNI plugins such as Cilium and Calico, and network operating systems including VyOS and OPNsense. No warning is emitted by wg, wg-quick, or the kernel on overwrite, and the longest-prefix-match lookup ensures only equal-length prefixes collide. The root cause resides in allowedips.c where rcu_assign_pointer redirects the trie node and list_move_tail detaches it from the original peer. The same logic appears across Linux, wireguard-go, wireguard-nt, FreeBSD, and OpenBSD implementations.
RCQ Messenger Duress PIN Flaw Gave Full Access to Real Database on Android
RCQ developers discovered that their duress PIN feature on Android used the same dataKey for both real and decoy accounts, allowing anyone entering the panic code to unlock the entire message history. The original design aimed to present a believable second account but resulted in the decoy PIN acting as a master key rather than a protective boundary. On iOS the implementation was cryptographically separate yet suffered from contact wiping that made the decoy mode look suspiciously empty. After review the team switched both platforms to independent random keys, generated realistic conversation histories, and disabled network features in decoy mode to avoid server-side linkage. Legacy slots created before the fix remain marked as such and require users to set a new decoy PIN. The post-mortem also covers desktop Argon2id vault encryption, notification leakage risks, and why short PINs remain vulnerable to offline brute-force even with strong KDF parameters.
Multiple Critical Vulnerabilities Patched in IBM Db2 Mirror for i
IBM has disclosed 18 vulnerabilities affecting the graphical user interface of its Db2 Mirror for i database synchronization product, which replicates Db2 for i databases across multiple systems. The most severe issue, CVE-2026-17186, carries a CVSSv3.1 base score of 9.9 and allows remote execution of arbitrary CL commands due to improper neutralization of specific elements within commands. Additional high-severity flaws include CVE-2026-17184 (CVSS 9.8) enabling arbitrary code execution through external file and path control, and CVE-2026-17182 (CVSS 9.8) permitting authentication bypass via URI path validation failures to access or modify sensitive data. Further issues encompass path traversal for writing files to arbitrary locations (CVE-2026-17181, CVSS 9.3) and an authorization bypass (CVE-2026-16879, CVSS 8.8). The vulnerabilities impact versions 7.6, 7.5, and 7.4, with fixes released in the August 11 security advisory.