NCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter
SAP has patched a vulnerability in the Data Hub Adapter for SAP Commerce Cloud. An unauthenticated attacker can exploit the vulnerability to execute arbitrary code. To do so, the attacker must send malicious network traffic to the Data Hub Adapter. Security firm Defused reports that attackers are actively scanning and searching for vulnerable Data Hub Adapter systems.
CSIRTS triage
- What
- An unauthenticated attacker can execute arbitrary code by sending malicious network traffic to the Data Hub Adapter.
- Who is affected
- Organizations running SAP Commerce Cloud Data Hub Adapter are affected; authentication is not required for exploitation.
- Urgency
- High urgency because attackers are actively scanning for vulnerable instances and the vulnerability allows unauthenticated remote code execution.
- Action
- Apply the security patch released by SAP immediately to all affected Data Hub Adapter deployments.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Commerce Cloud Data Hub Adapter
Get an email when a new Commerce Cloud Data Hub Adapter advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0302
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-582310.73% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 51% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-58231 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for SAP Commerce Cloud
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-58231: SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client…nvd · 2026-08-11
- criticalCVE-2026-44761: SAP Commerce Cloud could retain a sample OAuth2 client with publicly documented sample credent…nvd · 2026-07-14
- criticalexploitedCVE-2019-0344: SAP Commerce Cloud Deserialization of Untrusted Data Vulnerabilitycisa-kev · 2024-09-30
More from NCSC-NL Advisories
- unknownNCSC-2026-0301 [1.00] [M/H] Vulnerabilities patched in IBM i operating system by IBM2026-08-14
- unknownNCSC-2026-0300 [1.00] [M/H] Vulnerabilities patched in Fortinet FortiWeb2026-08-13
- unknownNCSC-2026-0299 [1.00] [M/H] Vulnerability patched in Fortinet FortiManager2026-08-13
- unknownNCSC-2026-0298 [1.00] [M/H] Vulnerabilities patched in Autodesk AutoCAD2026-08-13
- unknownNCSC-2026-0297 [1.00] [M/H] Vulnerabilities patched in GitLab Enterprise Edition and Community Edition2026-08-13