Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
Filtered Reports
7 / 9 results
criticalbug_reportVulnerabilitySAP Commerce Cloud, NetWeaver, MII: 4 critical flaws, 1 exploited
SAP Commerce Cloud, SAP NetWeaver, and SAP Manufacturing Integration and Intelligence (MII). Specific versions not disclosed in available data. At least 4 critical vulnerabilities confirmed.
criticalbug_reportVulnerabilitySAP Commerce Cloud CVE-2026-58231 under active exploit, 3 days post-patch
SAP Commerce Cloud, all versions prior to patched release levels. Vulnerability affects default authentication clients and endpoints lacking input validation. Unauthenticated remote exploitation possible.
criticalbug_reportVulnerabilitySAP Commerce Cloud RCE flaw (CVE-2026-58231) exploited 3 days post-patch
SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America.
criticalbug_reportVulnerabilitySAP Commerce Cloud critical flaw allows unauthenticated RCE (CVSS 10.0)
SAP Commerce Cloud (Data Hub Adapter). All unpatched versions are affected. The vulnerability impacts the default authentication client and certain functions lacking input validation.
criticalbug_reportVulnerabilityFortinet FortiSandbox command injection flaw enables remote code execution
Fortinet FortiSandbox products affected by CVE-2026-25089 (CVSS 9.1). Specific vulnerable versions not disclosed in provided data. Ivanti and SAP also released patches for separate critical vulnerabilities.
criticalbug_reportVulnerabilitySAP June 2026 patches fix 4 critical flaws in NetWeaver, Commerce Cloud
SAP NetWeaver and SAP Commerce Cloud products. Total of 15 vulnerabilities patched, including 4 critical-severity issues. Specific affected versions not disclosed in summary.
criticalbug_reportVulnerabilitySAP releases critical patches for multiple products
Multiple SAP products affected. Specific product names and versions not disclosed in available information. Patches released by SAP to address critical-severity vulnerabilities.