Actors
Malware
Campaigns
CVEs
Feed
Blog
Home
/
CVEs
/
CVE-2026-22732
CVE
CVE-2026-22732
View on NVD ↗
Under Some Conditions Spring Security HTTP Headers Are not Written
MITRE ATT&CK TTPs
1
T1190
Exploit Public-Facing Application
Initial Access
Source Articles
Max severity SAP Commerce Cloud flaw now targeted in attacks
A critical remote code execution vulnerability, CVE-2026-58231, in SAP Commerce Cloud is being actively exploited in the wild just three days after the patch was released. The flaw, which has a CVSS score of 10.0, stems from improper authorization in the Data Hub Adapter extension, allowing unauthenticated attackers to execute arbitrary code by exploiting a default authentication client. Threat intelligence firm Defused confirmed exploitation attempts are already occurring, as observed through honeypot traffic, despite the absence of a public proof-of-concept. The vulnerability affects internet-exposed SAP Commerce Cloud instances, with over 4,200 such systems identified globally, primarily in Europe and North America.
bleeping-computer
Aug 14, 2026