Affected Systems

SAP Commerce Cloud (formerly Hybris), specifically the core Data Hub Adapter extension. All unpatched instances are vulnerable. Shadowserver tracks 4,200+ internet-exposed instances, primarily in Europe and North America. Used by major global retailers and e-commerce brands.

Exploitation Status

Active exploitation confirmed by Defused threat intelligence on August 14, 2026, three days after patch release (August 11, 2026). Exploitation attempts observed against honeypots. No public PoC available at time of reporting. Unauthenticated remote code execution with CVSS 10.0 severity.

Business Impact

Unauthenticated attackers can execute arbitrary code remotely with low attack complexity. Successful exploitation compromises confidentiality, integrity, and availability of Commerce Cloud platforms handling customer transactions and sensitive retail data. Given SAP's customer base (99 of top 100 global companies), breach potential affects major e-commerce operations. Rapid exploitation window (72 hours) indicates attacker awareness and capability.

Urgency

🔴 Immediate

Recommended Actions

  • Apply SAP Security Note 3771065 immediately to all SAP Commerce Cloud instances, prioritizing internet-facing deployments
  • Audit network logs for unauthorized access attempts to Data Hub Adapter endpoints, focusing on authentication client abuse patterns shown in Defused's honeypot data
  • Verify that default authentication clients in Commerce Cloud are disabled or properly restricted per SAP hardening guidance
  • Conduct emergency asset inventory to identify all SAP Commerce Cloud instances (including dev/test environments) and confirm patch status
  • Monitor for unusual process execution, outbound connections, or lateral movement from Commerce Cloud servers as indicators of compromise