SAP Commerce Cloud: Critical severity e-commerce vulnerability exploited in active campaign within 3 days

Cybersecurity Aug 14, 2026Add to bookmarks

Cybersecurity

An unauthenticated RCE vulnerability in SAP Commerce Cloud is already being targeted by attackers three days after the patch. Large enterprise B2B and B2C e-commerce platforms are in the crosshairs.

What

A maximum severity vulnerability affecting SAP Commerce Cloud (formerly SAP Hybris, SAP's enterprise e-commerce platform) is being actively exploited—just three days after the patch was released. The flaw enables RCE (Remote Code Execution) without prior authentication. The alert comes from threat intelligence firm Defused.

Who is impacted

SAP Commerce Cloud powers the B2B and B2C e-commerce platforms of many large enterprises—retailers, manufacturers, distributors. If your organization hosts an SAP Commerce Cloud instance with internet access, treat this warning as critical.

Analysis

The time between patch release and active exploitation is shrinking every year. Three days is now a common window for critical vulnerabilities in widely deployed software: attackers automate reverse engineering of patches to extract technical details of the flaw before most organizations have time to deploy the update.

SAP Commerce Cloud presents an especially attractive attack surface:

  • Native internet exposure: it’s an e-commerce platform, designed to be publicly accessible
  • Sensitive data: customer information, order histories, payment data, backend ERP connections
  • Complex update cycles: in SAP environments, updates often go through long internal validation processes

Unauthenticated RCE is the most severe scenario: an attacker with no valid credentials can execute arbitrary code on the server.

3 days

This is the measured gap between SAP’s patch release and the first documented active exploit by Defused. The critical patching window now measures in hours, not weeks.

What to do now

  1. Identify all your SAP Commerce Cloud instances—including staging and UAT environments often overlooked during urgent patching cycles.
  2. Apply the SAP patch immediately via your SAP Support Portal (Security Note).
  3. Audit access logs from the date the flaw was published to detect any pre-patch exploitation attempts.
  4. Isolate unpatched instances behind a WAF (Web Application Firewall) in blocking mode until deployment is complete.
Resources, try it

Article produced by artificial intelligence, reviewed under human editorial control.

Our newsroom
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

SSHSelf-hostedAI Ops
Get early access
Was this article helpful?

12 people liked this article

Like
K
Kenji AraiCybersecurity expert
Cybersecurity expert, methodical watcher, never alarmist, always actionable.
Share:
Your Linux server, as a desktop.
TermalOSSponsored
Ops, reimagined

Your Linux server, as a desktop.

Agentless SSH monitoring, a full remote desktop and an AI ops copilot — no agents to install, everything stays on your machine.

Get early access
LIVERadio Geek Kitsune
Tap to listen, the same sound for everyone
0··
// Schedule
// all stations
// share a track →
Topics
Explore
Information