CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0302 [1.00] [M/H] Vulnerabilities patched in SAP Commerce Cloud Data Hub Adapter

unknownpublic exploitCVE-2026-58231
SAP has patched a vulnerability in the Data Hub Adapter for SAP Commerce Cloud. An unauthenticated attacker can exploit the vulnerability to execute arbitrary code. To do so, the attacker must send malicious network traffic to the Data Hub Adapter. Security firm Defused reports that attackers are actively scanning and searching for vulnerable Data Hub Adapter systems.

CSIRTS triage

What
An unauthenticated attacker can execute arbitrary code by sending malicious network traffic to the Data Hub Adapter.
Who is affected
Organizations running SAP Commerce Cloud Data Hub Adapter are affected; authentication is not required for exploitation.
Urgency
High urgency because attackers are actively scanning for vulnerable instances and the vulnerability allows unauthenticated remote code execution.
Action
Apply the security patch released by SAP immediately to all affected Data Hub Adapter deployments.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Commerce Cloud Data Hub Adapter

Get an email when a new Commerce Cloud Data Hub Adapter advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-15
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0302

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-58231coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for SAP Commerce Cloud

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories