Actively Exploited: Max-Severity RCE in SAP Commerce Cloud Under Attack Days After Patch
What Happened
Threat intelligence company Defused reports that a maximum-severity remote code execution vulnerability in SAP Commerce Cloud is already being targeted in the wild — just three days after SAP released a patch. The report does not specify a CVE identifier, technical exploitation details, or confirmed victims; those specifics were not included in the source reporting available at publication time.
Why It Matters
SAP Commerce Cloud (formerly Hybris) is widely used as an e-commerce and customer-experience backbone by large enterprises, meaning a max-severity RCE affects systems that typically process sensitive customer, order, and payment-adjacent data. A short three-day window between patch release and observed in-the-wild targeting is a familiar pattern for critical enterprise software: attackers frequently reverse-engineer vendor patches to weaponize the underlying flaw faster than organizations can apply fixes, leaving unpatched instances exposed almost immediately.
Who Is Affected
Organizations running self-managed or hybrid deployments of SAP Commerce Cloud that have not yet applied the recent SAP patch are at risk. Exact affected version ranges were not detailed in the available reporting — defenders should consult SAP's official advisory directly for patch identifiers and applicability.
What Defenders Should Do Now
- Patch immediately. Apply SAP's latest Commerce Cloud security update without delay given confirmed active exploitation.
- Check exposure. Inventory internet-facing and internally-reachable SAP Commerce Cloud instances; RCE flaws in customer-facing platforms are frequently reachable without authentication.
- Hunt for post-exploitation activity. Look for anomalous process spawning from SAP Commerce Cloud application server processes (e.g., unexpected shell or script execution), unusual outbound connections from Commerce Cloud hosts, and unexpected file writes to web-accessible directories that could indicate webshell deployment.
- Review authentication and admin logs for SAP Commerce Cloud around the patch release date for anomalous access patterns predating detection.
- Monitor vendor and CERT channels for IOCs, a formal CVE assignment, and exploitation TTPs as they become available.
Developing Story
This is early-stage, developing intelligence based on a single threat intelligence source (Defused) as reported by BleepingComputer. No CVE identifier, technical exploit chain, or confirmed victim organizations have been publicly detailed at this time. We will track this item for updates. Read the original report at BleepingComputer.