SAP has issued patches to mitigate a high-severity vulnerability affecting the Commerce Cloud (Data Hub Adapter), which may lead to remote code execution This article explores sap issued patches. . According to CVE.org, "SAP Commerce Cloud allows an unauthenticated attacker to exploit a default authentication client by submitting specially crafted input to certain functions lacking sufficient validation."

This results in arbitrary code execution and compromise of internal components, leading to high impact on confidentiality, integrity, and availability of the application. Onapsis advises customers to patch their Commerce Cloud release and then deploy the updated version of SAP Commerce Cloud. CVE-2026-44772 (Manufacturing Integration and Intelligence) - An injection flaw within the DIAG protocol parsing of Application Server ABAP for SAP NetWeaver and ABAP Platform, enabling unauthorized access through logical errors in the code.

After applying the patch, users must preserve the newly configured system property 'Secure Transformer', which includes a list of permitted hosts where XSL files are accessible to the vulnerable servlet.