Last updated: August 19, 2026 at 1:47 AM UTC
All 741 Vulnerability 286 Breach 129 Threat 319 Defense 7
Tag: e-commerce (3 articles)Clear

Critical SAP Commerce Cloud flaw exploited days after patch with no public exploit

Attackers began exploiting a critical SAP Commerce Cloud flaw within days of its patch, even though no public proof-of-concept exists. Tracked as CVE-2026-58231 and scored 10.0, the improper-authorization bug in the Data Hub Adapter lets an unauthenticated attacker abuse a default authentication client and send crafted input to reach arbitrary code execution. Threat intelligence firm Defused saw the first exploitation attempts hit its honeypots three days after SAP's August patch, classified as automated mass scanning of internet-facing deployments. Shadowserver tracks more than 4,200 exposed SAP Commerce Cloud systems, mostly in Europe and North America. Prior critical SAP flaws have been used by state actors and ransomware crews.

Check
Apply SAP's August patch for Commerce Cloud immediately per Security Note 3771065, then re-deploy the updated version, and prioritize any internet-facing or hybrid deployment as an emergency.
Affected
Organizations running unpatched SAP Commerce Cloud (CVE-2026-58231); an unauthenticated attacker can reach arbitrary code execution with low complexity, and exploitation is already underway despite no public exploit code.
Fix
Patch and re-deploy now, restrict access to Commerce Cloud from untrusted networks, review the Data Hub Adapter and application logs for suspicious requests and code execution, and monitor for follow-on compromise.

Adobe Commerce session flaw lets unauthenticated attackers take over customer accounts

Adobe patched a critical flaw in its Commerce and Magento e-commerce platforms that lets an unauthenticated attacker hijack customer accounts, and security firm Sansec reports its web application firewall is already blocking exploitation attempts. Tracked as CVE-2026-71362 and scored 9.1, the incorrect-authorization bug stems from the platform failing to bind a customer identity to an account session, so an attacker with only network access to the public storefront can switch an active session to another customer and read their private data. It needs no account, administrator rights, or user interaction. Adobe ships the fix as isolated patch files, so administrators must be on the latest point release first.

Check
Apply Adobe's August isolated patch for Commerce, Commerce B2B, and Magento after confirming you are on the latest point release for your branch, and treat exploitation traffic as already present.
Affected
Merchants running Adobe Commerce 2.4.4 to 2.4.9 or Magento Open Source 2.4.6 to 2.4.9 (CVE-2026-71362); an unauthenticated visitor can switch into another customer's session and access their account data.
Fix
Patch promptly, put a web application firewall in front of the storefront, review privileged account activity and unexpected configuration changes, and validate extension integrity on internet-facing Commerce instances.

Skoda Auto's German online shop breached via e-commerce software flaw - customer names, addresses, phones, and password hashes exposed; server logs cannot confirm full exfiltration

Skoda Auto, the Volkswagen Group's Czech-built carmaker with 34,000 employees and 27 billion euros in annual sales, disclosed that attackers exploited a flaw in its German online shop software to access customer data. The breach hit shop.skoda-auto.de, not Skoda's global systems or the Skoda Connect portal. Exposed information includes names, addresses, email addresses, phone numbers, order history, account data, and password hashes. Payment card details were not stored on the affected system. Skoda took the shop offline, patched the flaw, and engaged external forensics, but admitted its server logs cannot retrospectively confirm exactly what data was copied out during the intrusion window.

Check
Check the email account used for any past Skoda online shop orders, search your password manager for credentials reused across Skoda and other services, and watch for German-language phishing referencing real order numbers.
Affected
Customers who created an account or placed an order on shop.skoda-auto.de (Skoda Auto Germany's online store). The Skoda Connect Portal and Skoda's global systems are not affected per the company.
Fix
Change the Skoda online shop password and any other service using the same credentials, and enable MFA where available. Do not click links in emails or texts about Skoda orders; verify directly through the shop website.