SAP patched CVE-2026-31157 in Commerce Cloud on August 13 with a maximum CVSS score, remote code execution requiring no authentication. Defused, the threat intelligence firm tracking exploitation, logged active scanning and payload delivery against unpatched instances within seventy-two hours. The vendor advisory framed the fix as routine hardening. The exploitation timeline framed it as a countdown SAP lost.
Commerce Cloud sits in front of payment processing and customer PII for retailers running SAP's e-commerce stack, which means the instances still exposed are not edge cases, they are the ones that missed a patch cycle over a August weekend. The control that would have changed this outcome is not a WAF rule written after Defused's disclosure. It is a patch SLA under seventy-two hours for internet-facing SAP infrastructure, the same window the attackers used.