Skip to content
feed: live
>_0dayNews
sap

SAP Commerce Cloud RCE Exploit Hits Days After Patch

Defused flagged active exploitation of a max-severity SAP Commerce Cloud RCE within 72 hours of patching. Unpatched instances are live targets now.

SAP Commerce Cloud RCE Exploit Hits Days After Patch
Image: AI-generated — no human photographer / 0dayNews AI Cover · Generated on-site infrastructure — no external license
fuseMarisol "Fuse" Delgado·Published ·2 min read

Patch released. Exploitation started. Seventy-two hours is not a remediation window — it is the distance between “patched” and “breached.”

Threat intelligence company Defused confirmed active attacks against a maximum-severity remote code execution vulnerability in SAP Commerce Cloud, with exploitation traffic observed within three days of SAP’s patch release. The fix was part of SAP’s August 2026 Security Patch Day cycle.

What Happened

SAP’s August Security Patch Day included a maximum-severity RCE affecting Commerce Cloud. Within days, Defused observed active exploitation attempts in the wild. The vulnerability class is remote code execution — meaning an attacker who reaches a vulnerable instance can run arbitrary code on the underlying server without needing to authenticate first, or with minimal access depending on the specific flaw.

No CVE number was included in feed sources at time of writing. BleepingComputer’s report carries the full technical detail from Defused; follow it for version specifics and indicators of compromise.

Why Commerce Cloud Is a High-Value Target

SAP Commerce Cloud is the e-commerce and B2B portal backbone for some of the world’s largest companies — manufacturing, retail, consumer goods, energy. An RCE on an internet-facing Commerce Cloud instance can provide access to customer PII, payment integrations, and internal SAP system connections. Maximum severity on a platform like this means maximum business impact. Attackers know that.

What to Do

  1. Apply the August 2026 SAP Security Patch Day updates now. If your SAP basis team or managed service provider hasn’t confirmed this cycle is complete for Commerce Cloud, that conversation happens today.
  2. Prioritize Commerce Cloud over lower-severity items. If your patch schedule is phased, move this to the front.
  3. Check the SAP Support Portal for the specific security note, affected version ranges, and any available workarounds if immediate patching is not possible.
  4. Review Commerce Cloud application logs for anomalous behavior — unexpected process spawns, unusual outbound network connections, or irregular API calls from the application tier.
  5. Audit network exposure. Administration interfaces should not be internet-reachable. If they are, restrict access to known IP ranges immediately while patching proceeds.

The Honest Timeline

Three-day patch-to-exploit turnaround on a max-severity enterprise platform flaw is not unusual anymore — it is the baseline. Automated patch-diffing lets attackers reverse-engineer a fix and reconstruct the vulnerability faster than most organizations can schedule a maintenance window.

The remediation window your organization’s patch policy assumes probably does not account for this. If your policy says “patch critical vulnerabilities within 30 days,” that policy is writing checks your security posture cannot cash.

Patch Commerce Cloud. Then review your logs as if you were already compromised — on a three-day exploitation timeline, verifying you are not is worth the hour it takes.

Related: GeoServer Zero-Day SQL Injection Exploited in WildWordPress 7.0.4 Patches High-Severity RCE Flaw


Source: BleepingComputer — Max severity SAP Commerce Cloud flaw now targeted in attacks

Found this useful? Share it.