Act
active
Max-Severity SAP Commerce Cloud RCE Exploited in Active Attacks
- Engineer — Act: A max-severity RCE in SAP Commerce Cloud is under active attack just days after patching — apply the SAP patch immediately and audit Commerce Cloud logs for signs of pre-patch compromise.
- SOC/IR — Act: Active exploitation is confirmed by threat intelligence, so sweep SAP Commerce Cloud application and access logs for anomalous activity indicative of RCE or post-exploitation behavior since the patch release date.
- Leader — Act: Confirm whether your organization runs SAP Commerce Cloud and verify the emergency patch has been applied; if patching is delayed, request an incident status from the team given active exploitation is already underway.
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.