Daily Wire · Free EditionConfirmed Threats. Zero Noise.

The Exploit Bulletin

What Security Teams Must Act On Today

From the edition of

Tuesday, August 18, 2026

Remote Code ExecutioncriticalCVSS 10.0CVE-2026-58231

Unauthenticated RCE via Default Auth Client in SAP Commerce Cloud Data Hub Adapter (CVE-2026-58231)

VulnCheck added this CVSS 10.0 flaw to its known-exploited catalog on 2026-08-14 and Security Affairs confirmed in-the-wild attacks the next day, so unpatched Data Hub Adapter instances are being probed and compromised right now.

A default authentication client in the SAP Commerce Cloud Data Hub Adapter lets an unauthenticated remote attacker submit crafted input to functions lacking validation, achieving arbitrary code execution and full compromise of confidentiality, integrity, and availability of internal components. The CVSS 3.1 score is a maximum 10.0 with a network, no-privileges, no-interaction, scope-changed vector.

Affected: SAP Commerce Cloud (Data Hub Adapter) COM_CLOUD 2211; SAP Commerce Cloud (Data Hub Adapter) 2211-JDK21

How to Test

Inventory whether your SAP Commerce Cloud 2211 or 2211-JDK21 deployment includes the Data Hub Adapter extension and whether its endpoints are reachable from the internet; check that the default authentication client shipped with the adapter has not been left enabled with stock credentials. Review web/application access logs for unauthenticated requests hitting Data Hub Adapter endpoints, especially unexpected POSTs with crafted payloads since mid-August 2026, and look for anomalous processes or outbound connections from the Commerce application nodes.

How to Patch

Apply SAP Security Note 3771065 (released on SAP Security Patch Day) to the Data Hub Adapter on COM_CLOUD 2211 / 2211-JDK21 immediately. If patching cannot happen today, disable or remove the default authentication client used by the Data Hub Adapter, restrict network access to the adapter endpoints to trusted integration hosts only, and treat any exposed unpatched instance as potentially compromised pending forensic review.