A maximum-severity remote code execution (RCE) vulnerability in SAP Commerce Cloud — patched just three days ago — is already being actively targeted in attacks, according to threat intelligence firm Defused. The speed of weaponization underscores the increasingly narrow window organizations have to apply patches before adversaries begin exploiting them.
The Vulnerability
The flaw carries a CVSS score of 10.0, representing a complete compromise of confidentiality, integrity, and availability. SAP Commerce Cloud, formerly known as SAP Hybris, is a widely deployed enterprise e-commerce platform used by major retailers and B2B organizations globally. A successful exploit would allow an unauthenticated remote attacker to execute arbitrary code on affected servers, potentially leading to full system takeover, data exfiltration, or lateral movement into connected infrastructure.
SAP released the patch as part of a recent security update cycle. However, threat intelligence monitoring indicates that proof-of-concept exploit code or operational techniques began circulating shortly after the advisory was published — a pattern increasingly common with high-profile enterprise software vulnerabilities.
Active Exploitation
Defused's threat intelligence reports confirmed observations of exploitation attempts in the wild targeting the SAP Commerce Cloud endpoint. The nature of the attacks and the threat actors involved have not been fully disclosed, but the campaign highlights a persistent trend: enterprise software vulnerabilities with public advisories are now being weaponized within hours to days, rather than weeks.
SAP's large enterprise customer base makes this particularly attractive for threat actors seeking to compromise high-value targets, including e-commerce platforms that process financial transactions and store sensitive customer data.
Who Is at Risk
Organizations running SAP Commerce Cloud (any edition) that have not yet applied the latest security patch are at immediate risk. This includes:
- Enterprise retailers and e-commerce operators
- B2B organizations using SAP's commerce platform
- Cloud-hosted SAP deployments that are internet-facing or accessible via partner networks
Recommended Actions
- Patch immediately — apply the SAP security patch released in the most recent update cycle without delay. Do not wait for a scheduled maintenance window.
- Check your exposure — identify all SAP Commerce Cloud instances in your environment, including staging and QA systems, which may be reachable from the internet.
- Implement WAF / network controls — if immediate patching is not possible, use a web application firewall or network segmentation to restrict access to the affected endpoints.
- Monitor for indicators of compromise — watch for anomalous outbound connections, unexpected process execution on SAP hosts, or unusual access to configuration endpoints.
- Engage your vendor / managed security provider — if you are unsure of your patch status, contact your SAP support channel immediately.
Context: The Narrowing Patch Window
The rapid exploitation of this SAP flaw is part of a broader pattern. High-profile vulnerabilities in enterprise platforms such as Confluence, Exchange, Citrix, and others have seen exploitation begin within 24–72 hours of disclosure. Security teams can no longer treat patch cycles as routine — critical and max-severity vulnerabilities in internet-facing products must be treated as emergency response scenarios.