Skip to content

company

Defused

Threat intelligence firm whose honeypots recorded exploitation attempts against CVE-2026-55040 on August 12 using Rapid7's PoC.

Known aliases

  • Defused Cyber
  • Defused researchers

Relationships

No evidence-backed relationships are recorded.

Current stories

security5 publishers

Three days from patch to probe: SAP Commerce Cloud RCE is already being hunted

CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.

Perspective Coverage

5 publishers
Builder
Builder 26%
Operator
Operator 65%
Investor
Investor 9%

Reality

Evidence70
Adoption55
Hype gap+25
Incentives40
Confidence68
security7 publishers

Citrix called it a crash bug. It is unauthenticated RCE, and CISA gave agencies three days.

CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.

Perspective Coverage

7 publishers
Builder
Builder 14%
Operator
Operator 80%
Investor
Investor 6%

Reality

Evidence78
Adoption50
Hype gap−40
Incentives
Insufficient
Confidence74