A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused.

SAP fixes CVE-2026-58231, a CVSS 10.0 Commerce Cloud flaw that could let unauthenticated attackers execute arbitrary code.

Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack…