Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical SAP Commerce Cloud Vulnerability Alert

Critical SAP Commerce Cloud Vulnerability Alert

Posted on August 12, 2026 By CWS

SAP has announced a crucial update to mitigate a severe security flaw in its Commerce Cloud platform, specifically the Data Hub Adapter. This flaw, identified as CVE-2026-58231, carries a maximum severity score of 10.0 on the CVSS scale, posing a significant threat of arbitrary code execution.

Understanding the Vulnerability

The vulnerability arises from inadequate authorization checks and insufficient input validation. This issue allows an unauthenticated attacker to manipulate a default authentication client and introduce specially crafted inputs into certain functions. The consequences of exploiting this flaw include potential arbitrary code execution, thereby threatening the confidentiality, integrity, and availability of the affected applications.

Security experts from Onapsis emphasize the urgency for users to apply the latest patches for SAP Commerce Cloud. As an interim measure, configuring an IP Filter Set to limit access to vulnerable endpoints is recommended until the fix is fully implemented.

Additional Critical Vulnerabilities in August Update

In addition to the Commerce Cloud flaw, SAP’s August 2026 update addresses three other critical vulnerabilities. One of these, CVE-2026-44772, involves a code injection risk in Manufacturing Integration and Intelligence, with a CVSS score of 9.9. Another, CVE-2026-34265, pertains to an out-of-bounds write issue in Application Server ABAP, scoring 9.8, which could lead to system information exposure or crashes due to errors in DIAG protocol parsing.

Furthermore, CVE-2026-44758, also related to code injection in Manufacturing Integration, poses a threat of arbitrary command execution by attackers with high-level privileges. The patch for this vulnerability removes a servlet component vulnerable to server-side template injection (SSTI) and server-side request forgery (SSRF).

Protecting Your Systems

Onapsis advises that after applying patches, customers should configure a new system property named ‘Secure Transformer’ to permit only certain hosts for XSL file hosting. This measure ensures that only authorized XSL files can be processed by the vulnerable servlet component.

These updates underscore the importance of maintaining up-to-date security measures to protect enterprise systems from potential cyber threats. SAP users are strongly encouraged to implement the recommended patches and precautions promptly to safeguard their infrastructures.

The Hacker News Tags:August 2026 update, Authorization, code execution, Commerce Cloud, CVE-2026-58231, Cybersecurity, enterprise security, input validation, IP Filter Set, Onapsis, Patch, SAP, security flaw, server-side request forgery, server-side template injection, Vulnerability

Post navigation

Previous Post: Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment
Next Post: August 2026 ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact Updates

Related Posts

SysAid Flaws Under Active Attack Enable Remote File Access and SSRF SysAid Flaws Under Active Attack Enable Remote File Access and SSRF The Hacker News
How CISOs Can Drive Effective AI Governance How CISOs Can Drive Effective AI Governance The Hacker News
Weekly Cybersecurity Update: Major Breaches and Vulnerabilities Weekly Cybersecurity Update: Major Breaches and Vulnerabilities The Hacker News
CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat CTM360 Exposes a Global WhatsApp Hijacking Campaign: HackOnChat The Hacker News
Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy Google Launches ‘Private AI Compute’ — Secure AI Processing with On-Device-Level Privacy The Hacker News
Critical Metabase Flaw Exploited, Urgent Patch Released Critical Metabase Flaw Exploited, Urgent Patch Released The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • North Korean Hackers Exploit Fresh Windows Vulnerability
  • LiteLLM Malicious Releases Impact Over 2,500 Organizations
  • August 2026 ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact Updates
  • Critical SAP Commerce Cloud Vulnerability Alert
  • Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • North Korean Hackers Exploit Fresh Windows Vulnerability
  • LiteLLM Malicious Releases Impact Over 2,500 Organizations
  • August 2026 ICS Patch Tuesday: Siemens, Schneider, Phoenix Contact Updates
  • Critical SAP Commerce Cloud Vulnerability Alert
  • Lazarus Group Exploits Windows Vulnerability for Rootkit Deployment

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark