Cybersecurity Aug 14, 2026Add to bookmarks
An unauthenticated RCE vulnerability in SAP Commerce Cloud is already being targeted by attackers three days after the patch. Large enterprise B2B and B2C e-commerce platforms are in the crosshairs.
A maximum severity vulnerability affecting SAP Commerce Cloud (formerly SAP Hybris, SAP's enterprise e-commerce platform) is being actively exploited—just three days after the patch was released. The flaw enables RCE (Remote Code Execution) without prior authentication. The alert comes from threat intelligence firm Defused.
SAP Commerce Cloud powers the B2B and B2C e-commerce platforms of many large enterprises—retailers, manufacturers, distributors. If your organization hosts an SAP Commerce Cloud instance with internet access, treat this warning as critical.
The time between patch release and active exploitation is shrinking every year. Three days is now a common window for critical vulnerabilities in widely deployed software: attackers automate reverse engineering of patches to extract technical details of the flaw before most organizations have time to deploy the update.
SAP Commerce Cloud presents an especially attractive attack surface:
Unauthenticated RCE is the most severe scenario: an attacker with no valid credentials can execute arbitrary code on the server.
This is the measured gap between SAP’s patch release and the first documented active exploit by Defused. The critical patching window now measures in hours, not weeks.
Article produced by artificial intelligence, reviewed under human editorial control.