Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE

SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE 1. Basic Information Severity: Critical Article Title: Max severity SAP Commerce Cloud flaw now targeted in attacks Source: BleepingComputer Publication Date: 2026-08-14 Update Date: 2026-08-14 Original Article: Original Source Related Sources: SAP Security Patch Day - August 2026 , Onapsis Malware: None Groups:…

SAP Commerce Cloud contains a critical flaw, identified as CVE-2026-58231, that enables attackers to achieve remote code execution (RCE) without requiring any authentication. This vulnerability stems from a combination of default authentication client issues and input validation flaws in the Data Hub Adapter. The exploit has been actively attempted, as confirmed by a honeypot three days following the release of a security patch.

While the exact points of execution and post-exploitation activities remain undisclosed, the presence of numerous IP addresses associated with the product, as reported by Shadowserver, suggests a potential risk of unpatched, vulnerable, or compromised systems. On successful exploitation, attackers can gain unauthenticated arbitrary code execution, compromising internal components and severely impacting the application's confidentiality, integrity, and availability.

Immediate actions should include applying the noted security patch and implementing additional measures such as IP filtering and isolation of the Data Hub Adapter to mitigate the risk of attacks.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Day 14: AWS Compute — Managed & Serverless

We started the compute layer on Day 13 with EC2, ELB, and Auto Scaling — where you launch and manage everything yourself.

  • AWS Elastic Beanstalk simplifies deployment by managing EC2 instances and load balancing.
  • Amazon Lightsail offers pre-configured virtual servers with fixed pricing for common applications.

AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix

AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix 1. Basic Information Severity: High Article Title: AmnesiaStealer: a multi-stage Rust-based macOS infostealer that…

  • AmnesiaStealer is macOS-specific infostealer targeting Chromium browsers
  • Distributed via fake GitHub ClickFix page tricking users into executing shell script
  • Steals login passwords, Keychain data, documents, browser info using CDP control

macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation

macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation 1. Basic Information Severity: Critical Title: Hackers exploit macOS Screen Sharing flaw…

  • Authentication bypass vulnerability in macOS Screen Sharing exploited
  • Hackers gain root access and install Monero miner
  • Update macOS, disable Screen Sharing to mitigate risk

More from Saturday 15 August →