ON
← Back to feed
Patch day: SAP Commerce Cloud is fully vulnerable
Germany💻 Technology13 days ago

Patch day: SAP Commerce Cloud is fully vulnerable

A security update has been released by SAP to address multiple critical vulnerabilities in their Commerce Cloud and other software products. Attackers could exploit these flaws to gain full control over Commerce Cloud instances or execute malicious code without authentication. Four of the identified vulnerabilities are classified as 'critical,' including one with the highest possible CVSS score of 10. Additional issues affect manufacturing integration tools, application servers, and data analytics platforms, potentially allowing unauthorized access to sensitive information or system crashes. SAP customers can find more details about patched versions in their support portal.

A critical vulnerability in SAP's Commerce Cloud has been identified, allowing attackers to gain full control over instances of the business software. Security patches have been released by SAP to address these issues, following a detailed disclosure during the latest Patchday. The vulnerabilities, which include four classified as "critical," pose a serious risk to organizations using the affected systems. The vulnerabilities were disclosed in a report published by SAP developers during the Patchday event. According to the report, 40 Common Vulnerabilities and Exposures (CVE) numbers have been assigned to the resolved weaknesses. Among these, four flaws are categorized as critical. One such flaw, CVE-2026-58231, allows attackers to execute malicious code without authentication due to insufficient validation mechanisms. This particular vulnerability carries the highest possible CVSS score of 10 out of 10, indicating its severe impact potential. Another set of vulnerabilities affects the Manufacturing Integration and Intelligence component through two separate flaws, CVE-2026-44772 and CVE-2026-44758. These allow unauthorized access and execution of malicious payloads. Additionally, successful exploitation of the vulnerability CVE-2026-34265 within the Application Server ABAP for SAP NetWeaver and ABAP Platform could lead to system crashes, disrupting operations significantly. Beyond these critical issues, SAP addressed several other security concerns affecting components such as the ABAP Platform, BusinessObjects Business Intelligence, and Social Intelligence. These vulnerabilities can result in unauthorized access to sensitive data and the injection of malicious code onto affected systems. Such breaches could compromise data integrity and operational continuity. Customers utilizing SAP products are advised to consult the company’s support portal for detailed information regarding the patched versions and necessary updates. This resource provides specific guidance on implementing the fixes to secure their systems against the newly disclosed threats. The release of these patches underscores the importance of timely software maintenance and proactive security measures. Organizations relying on SAP solutions must ensure they apply all available updates promptly to mitigate risks associated with these vulnerabilities. SAP's ongoing efforts highlight the dynamic nature of cybersecurity challenges faced by enterprise software providers. As new threats emerge, continuous monitoring and updating of systems remain essential practices for maintaining robust defenses. The disclosed vulnerabilities serve as a reminder of the necessity for rigorous security protocols and regular audits of software environments. By addressing these issues swiftly, SAP aims to protect its users from potential exploits that could otherwise lead to significant disruptions and data breaches. Organizations should prioritize reviewing their current security configurations and ensuring compliance with the latest patch recommendations issued by SAP. This includes verifying that all relevant systems have received the necessary updates to prevent exploitation of the identified vulnerabilities. In light of these developments, IT departments are urged to conduct thorough assessments of their infrastructure to identify any exposed components that might still be vulnerable. Implementing additional layers of defense, such as intrusion detection systems and network segmentation, can further enhance protection against sophisticated cyber threats. The incident also highlights the broader implications of software vulnerabilities within complex enterprise ecosystems. As businesses increasingly rely on integrated digital platforms, the need for comprehensive security strategies becomes more pronounced. Continuous collaboration between software vendors and their customers is crucial in maintaining a resilient cybersecurity posture. SAP's response to this situation demonstrates the company's commitment to transparency and customer safety. By proactively disclosing these vulnerabilities and providing timely patches, SAP reinforces its role as a responsible provider of enterprise solutions. Customers are encouraged to stay informed and engaged with the vendor's security advisories to ensure their systems remain protected against evolving threats.

Go to the primary sources (2)

The official sources this coverage is built on. Read them directly to bypass framing.

1 reports

heise online logoheise onlineIndependentCenterFactual 95Objective 8513 days ago
Patch day: SAP Commerce Cloud is fully vulnerable

A security update has been released by SAP to address multiple critical vulnerabilities in their Commerce Cloud and other software products. Attackers could exploit these flaws to gain full control over Commerce Cloud instances or execute malicious code without authentication. Four of the identified vulnerabilities are classified as 'critical,' including one with the highest possible CVSS score of 10. Additional issues affect manufacturing integration tools, application servers, and data analytics platforms, potentially allowing unauthorized access to sensitive information or system crashes. SAP customers can find more details about patched versions in their support portal.

Bias read (Center): The article focuses on technical vulnerabilities in enterprise software and provides factual information about security patches. There is no political framing, bias, or commentary on policy, governance, or ideology. The content is purely technical and neutral in tone.

Why factuality (95): The article reports on SAP's security patches released during Patchday, citing specific CVE numbers and severity ratings. It aligns with typical industry reporting on software vulnerabilities and patch releases. The information appears consistent with standard cybersecurity reporting practices and d

Why objectivity (85): The tone remains professional and informative, focusing on technical details of the vulnerabilities and the response from SAP. However, there is a slight bias towards emphasizing the potential risks posed by the vulnerabilities, which may lean slightly toward alarmism rather than neutrality.

How each side covered it

The same event, grouped by the political lean of the outlets covering it.

How each side covered it

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Covered around the world

The same event as reported in other countries.

Covered around the world

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Claims check

Key factual claims, and how many sources assert vs dispute each.

Claims check

Support independent, bias-aware news and unlock the social pulse, community voting, and every other Supporter feature.

Become a Supporter

Keep the news honest.

ObjectiveNews is reader-funded and ad-free — we show you the bias instead of hiding it. Support independent journalism for €4/month.

Become a Supporter

Related stories