Dossier
Unauthenticated attackers
Coverage of Unauthenticated attackers in the Nexus archive.
- SAP Commerce Cloud Flaw Could Let Unauthenticated Attackers Execute Arbitrary Code
SAP has released patches addressing a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter). This vulnerability, designated CVE-2026-58231 and rated 10.0 on the CVSS scoring system, allows unauthenticated attackers to execute arbitrary code through insufficient authorization checks and input validation.
- Patch these critical Fortinet sandbox bugs that let attackers bypass login, run commands over HTTP
Two critical vulnerabilities in Fortinet's sandbox allow unauthenticated attackers to bypass login and execute unauthorized commands over HTTP. No active exploitation reports yet, but warnings urge vigilance against potential future attacks.