CVE-2026-58231 is an unauthenticated, CVSS 10.0 code execution bug in Commerce Cloud's Data Hub Adapter. Defused says attempts hit its honeypots three days after patch day.
Perspective Coverage
5 publishers
- Builder
- Builder 26%
- Operator
- Operator 65%
- Investor
- Investor 9%
Reality
- Evidence70
- Adoption55
- Hype gap+25
- Incentives40
- Confidence68
A third party published CVE-2026-63520 before the planned date, and two public gadget chains now reach the same flaw by different routes. One signature will not cover both.
Reality
- Evidence72
- Adoption40
- Hype gap+5
- Incentives45
- Confidence70
CVE-2026-8452 shipped as a June 30 denial-of-service fix. A WatchTowr proof of concept turned it into pre-auth code execution, and in-the-wild exploitation followed.
Perspective Coverage
7 publishers
- Builder
- Builder 14%
- Operator
- Operator 80%
- Investor
- Investor 6%
Reality
- Evidence78
- Adoption50
- Hype gap−40
- Incentives
- Insufficient
- Confidence74
PaperCut shipped emergency fixes for CVE-2026-81578 and CVE-2026-82078 on Thursday and Friday, and by the weekend Defused was watching honeypot intruders bypass authentication and read database tables instead of running code.
Reality
- Evidence62
- Adoption58
- Hype gap+18
- Incentives58
- Confidence60
ServiceNow fixed its own hosted fleet on August 27 and handed the same update to partners and self-hosted customers, whose unauthenticated GraphQL and SQL exposure stays open until someone on staff installs it.
Reality
- Evidence66
- Adoption32
- Hype gap+27
- Incentives68
- Confidence70
Attackers are forging tokens SharePoint accepts, then enumerating management APIs and probing Business Connectivity Services for the execution sink. BleepingComputer reports nobody has seen that last step land.
Reality
- Evidence55
- Adoption42
- Hype gap+18
- Incentives30
- Confidence48
CVE-2026-58231 chains a default auth client with missing input validation in SAP's Data Hub Adapter. The fix needs a rebuild and redeploy; the attackers needed 72 hours.
Reality
- Evidence42
- Adoption28
- Hype gap+12
- Incentives38
- Confidence44
CVE-2026-55040 was patched in July. Rapid7 published the technical details and a script on August 11, and Defused says its honeypots logged exploitation on August 12.
Reality
- Evidence58
- Adoption34
- Hype gap+12
- Incentives62
- Confidence57