<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Sap on CuraSec</title><link>https://curasec.metacog.co.kr/tags/sap/</link><description>Recent content in Sap on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Sat, 15 Aug 2026 11:32:14 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/sap/index.xml" rel="self" type="application/rss+xml"/><item><title>Max-Severity SAP Commerce Cloud RCE Exploited in Active Attacks</title><link>https://curasec.metacog.co.kr/insights/2026-08-15-max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/</link><pubDate>Sat, 15 Aug 2026 11:32:14 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-15-max-severity-sap-commerce-cloud-flaw-now-targeted-in-attacks/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> A max-severity RCE in SAP Commerce Cloud is under active attack just days after patching — apply the SAP patch immediately and audit Commerce Cloud logs for signs of pre-patch compromise.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation is confirmed by threat intelligence, so sweep SAP Commerce Cloud application and access logs for anomalous activity indicative of RCE or post-exploitation behavior since the patch release date.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether your organization runs SAP Commerce Cloud and verify the emergency patch has been applied; if patching is delayed, request an incident status from the team given active exploitation is already underway.&lt;/li>
&lt;/ul></description></item><item><title>SAP Commerce Cloud CVSS 10.0 Unauthenticated RCE Flaw Patched</title><link>https://curasec.metacog.co.kr/insights/2026-08-12-sap-commerce-cloud-flaw-could-let-unauthenticated-attackers/</link><pubDate>Wed, 12 Aug 2026 11:57:00 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-12-sap-commerce-cloud-flaw-could-let-unauthenticated-attackers/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Public PoC on GitHub for a CVSS 10.0 unauthenticated RCE in SAP Commerce Cloud Data Hub Adapter makes exploitation practical now; apply SAP&amp;rsquo;s patch for CVE-2026-58231 immediately and verify no unauthorized access to the Data Hub Adapter endpoint prior to patching.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> With a public PoC available for unauthenticated RCE, sweep web access logs for anomalous requests to SAP Commerce Cloud Data Hub Adapter endpoints and hunt for post-exploitation activity (unusual process spawns, lateral movement) on Commerce Cloud hosts since the disclosure date.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether your organization runs SAP Commerce Cloud and, if so, verify the engineering team has emergency-patched CVE-2026-58231; a public PoC for a max-severity unauthenticated RCE on an e-commerce platform warrants a same-week status check and potential customer notification if the platform handles transaction data.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-58231 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>SAP Patches CVSS 9.9 NetWeaver ABAP Out-of-Bounds Write Flaw</title><link>https://curasec.metacog.co.kr/insights/2026-07-15-sap-patches-cvss-9-9-netweaver-abap-flaw-that-could-expose-o/</link><pubDate>Wed, 15 Jul 2026 12:11:39 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-15-sap-patches-cvss-9-9-netweaver-abap-flaw-that-could-expose-o/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> SAP NetWeaver ABAP is widely deployed in enterprise environments and this authenticated out-of-bounds write carries a 9.9 CVSS; no KEV listing, EPSS near zero, and no public PoC mean there&amp;rsquo;s no immediate exploitation pressure, but apply SAP&amp;rsquo;s July 2026 security patches in your next maintenance window.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-44747 — CISA KEV: not listed, EPSS 0.00, no public PoC found&lt;/li>
&lt;/ul></description></item><item><title>SAP patches 3 critical flaws in NetWeaver, Commerce Cloud, AppRouter</title><link>https://curasec.metacog.co.kr/insights/2026-07-14-sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/</link><pubDate>Tue, 14 Jul 2026 12:08:08 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-14-sap-warns-of-critical-flaws-in-netweaver-and-commerce-cloud/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Plan:&lt;/strong> Three critical severity patches in widely deployed SAP products (NetWeaver, Commerce Cloud, AppRouter) warrant scheduling this sprint; no KEV listing or public PoC yet, but NetWeaver has been heavily targeted historically — apply July 2026 SAP Security Patch Day updates and verify no internet-exposed NetWeaver instances are lagging.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Skip&lt;/strong>&lt;/li>
&lt;li>&lt;strong>Leader — Learn:&lt;/strong> Routine SAP patch cycle with critical-severity items; if SAP NetWeaver or Commerce Cloud is in the enterprise stack, confirm with engineering that the July updates are in the patching queue — no breach or active exploitation requiring leadership escalation at this time.&lt;/li>
&lt;/ul></description></item></channel></rss>