SAP's August 2026 Security Patch Day includes a maximum-severity flaw in SAP Commerce Cloud's Data Hub Adapter that lets an unauthenticated remote attacker execute arbitrary code and compromise internal components. Rated CVSS 10.0, this is the highest severity vulnerability SAP has patched in 2026. No exploitation in the wild has been confirmed, but Onapsis is urging immediate patching and redeployment. The same patch cycle also closes three additional critical flaws across SAP NetWeaver and Manufacturing Integration and Intelligence.

What the Vulnerability Is

CVE-2026-58231 lives in SAP Commerce Cloud's Data Hub Adapter, a component that bridges Commerce Cloud with external data pipelines and backend systems. The root cause is a combination of insufficient authorization checks and missing input validation: the adapter ships with a default authentication client that can be abused by anyone on the network, and certain functions that client can reach do not validate the input they receive.

An unauthenticated attacker can send specially crafted requests to the vulnerable endpoint, triggering arbitrary code execution on the Commerce Cloud host. Because the Data Hub Adapter is typically exposed as part of the web-facing Commerce Cloud deployment, no credentials and no prior access are required — the vulnerability is reachable from the public internet if the endpoint is not filtered at the network layer.

A second SAP critical flaw disclosed the same day — CVE-2026-34265 (CVSS 9.8) in SAP NetWeaver Application Server ABAP — is a memory corruption bug rooted in logical errors in the DIAG protocol parser. That flaw is also exploitable without authentication and can disclose sensitive information or crash the application server. Two additional critical code injection bugs in SAP Manufacturing Integration and Intelligence (CVE-2026-44772, CVSS 9.9; CVE-2026-44758, CVSS 9.1) round out the critical-priority items for this patch cycle.

Why It Matters

  • CVSS 10.0 is the maximum score possible. A perfect-10 rating means the attack requires no privileges, no user interaction, and no special conditions, and results in complete compromise of confidentiality, integrity, and availability.
  • Commerce Cloud hosts e-commerce storefronts. Organizations running SAP Commerce Cloud (formerly Hybris) power high-traffic retail and B2B commerce sites. An unauthenticated code execution flaw on these servers exposes customer data, payment infrastructure, and backend SAP integrations.
  • Data Hub Adapter exposes a service endpoint. Unless access is restricted at the firewall level, the vulnerable endpoint is reachable over the internet. Attackers can probe for it without credentials.
  • Multiple critical SAP flaws in a single patch day. The August 2026 patch cycle includes four critical CVEs across different SAP products. Organizations with any SAP footprint should treat this as a wide-scope patching event.

Am I Affected?

You are affected if you run SAP Commerce Cloud (Data Hub Adapter), versions 2211 or 2211-JDK21 without the August 2026 SAP patch applied. You are also affected if you run SAP NetWeaver AS ABAP on any kernel version prior to the August 2026 patch (for CVE-2026-34265).

To confirm your Commerce Cloud version, log in to SAP Cloud Portal or your SAP Backoffice Admin and check Administration → Deployment Details. If you are on version 2211, confirm whether the August 2026 security update has been applied and the environment redeployed.

What to Do About It: Step-by-Step

1. Apply the August 2026 SAP Security Patch and redeploy.

For cloud-managed deployments, SAP will push the fix automatically. Confirm with your SAP account team that your instance is on the patched build. After patching, you must redeploy your SAP Commerce Cloud environment — patching alone is not sufficient to close the vulnerability.

For on-premises or IaaS Commerce Cloud deployments, download the patched release from the SAP Software Center, deploy it per your standard process, and verify the Data Hub Adapter is running the patched version post-deployment.

2. Apply the IP Filter Set workaround if patching must wait.

Until the patch can be applied, restrict access to the vulnerable Data Hub Adapter endpoint. In Commerce Cloud Backoffice, navigate to System → API and configure an IP Filter Set that limits access to known internal IP ranges only. This removes the network-reachable unauthenticated exposure while a maintenance window is arranged.

3. Patch CVE-2026-34265 (SAP NetWeaver ABAP) in the same window.

Apply the August 2026 NetWeaver AS ABAP kernel update from SAP's Security Patch Day notes. The unauthenticated DIAG protocol memory corruption bug can crash or disclose data from your ABAP application server.

4. Review all 28 SAP August 2026 Security Notes.

SAP released 28 new security notes and two updates on August 12, 2026. Review the full list at SAP's Security Patch Day portal and apply all Critical and High notes that apply to your SAP landscape.

5. Verify the Data Hub Adapter is not publicly exposed.

Even after patching, confirm that a perimeter firewall or WAF restricts the Data Hub Adapter endpoint to known internal and partner ranges, and that HTTPS is enforced on all Commerce Cloud endpoints.

Quick-Win Checklist

  • Confirm SAP Commerce Cloud version and patch status in SAP Cloud Portal or Backoffice
  • Apply August 2026 SAP Commerce Cloud patch and redeploy the environment
  • Apply IP Filter Set workaround immediately if patch deployment requires scheduled downtime
  • Apply CVE-2026-34265 NetWeaver AS ABAP kernel patch in the same maintenance window
  • Review all 28 SAP August 2026 Security Notes for other applicable patches
  • Verify the Data Hub Adapter endpoint is not publicly reachable (firewall, WAF)
  • Confirm with SAP account team if on cloud-managed deployment that auto-patch has been applied and redeployment triggered

Sources