Synced 17 Jun 2026 22:27 UTC Account
← Commerce Cloud

Commerce Cloud vulnerabilities: known CVEs & security history

SAP · Actively exploited · 18 tracked CVEs · 1 actively exploited · updated June 2026 · what is a CVE? →

This is the full list of known vulnerabilities (CVEs) across all Commerce Cloud release lines — 18 in total, with 1 actively exploited in the wild. A CVE here doesn't mean your version is affected — check Commerce Cloud's current status and the safe version to run.

18
known CVEs
1
actively exploited (KEV)
2
critical severity
0
ransomware-linked

Known Commerce Cloud CVEs

Actively-exploited and most-severe first. Open any CVE for full details.

CVESeverityCVSSEPSSYear
CVE-2019-0344⚡ exploited critical 9.8 7% 2019
CVE-2020-6238 critical 9.3 1% 2020
CVE-2023-39439 high 8.8 1% 2023
CVE-2019-0343 high 8.8 1% 2019
CVE-2023-42481 high 8.1 1% 2023
CVE-2019-0322 high 7.5 3% 2019
CVE-2024-33003 high 7.4 0% 2024
CVE-2021-33666 medium 6.1 1% 2021
CVE-2020-6201 medium 6.1 1% 2020
CVE-2026-23684 medium 5.9 0% 2026
CVE-2023-37486 medium 5.9 0% 2023
CVE-2021-21445 medium 5.4 1% 2021
CVE-2020-6272 medium 5.4 1% 2020
CVE-2020-6200 medium 5.4 1% 2020
CVE-2026-24321 medium 5.3 0% 2026
CVE-2020-26809 medium 5.3 2% 2020
CVE-2020-6232 medium 5.3 1% 2020
CVE-2020-6363 medium 4.6 1% 2020

Is my Commerce Cloud version affected?

The list above spans every release. To know whether your version is affected — and the minimum safe version to upgrade to — check it directly.

Check your Commerce Cloud version → · Monitor Commerce Cloud for new CVEs →

Commerce Cloud vulnerabilities — frequently asked

How many known vulnerabilities does Commerce Cloud have?

IsItPatched tracks 18 CVEs for Commerce Cloud, 1 of which is actively exploited (CISA KEV). 2 are critical-severity and 5 high-severity. These span every release line — what matters is whether the version you run is affected.

Does Commerce Cloud have any actively-exploited vulnerabilities?

Yes — 1 Commerce Cloud CVE is in CISA's Known Exploited Vulnerabilities catalog, meaning it is confirmed exploited in the wild. Patch it as a priority.

What is the most severe Commerce Cloud vulnerability?

Among tracked issues, CVE-2019-0344 (CRITICAL, CVSS 9.8), which is actively exploited, ranks highest — a Insecure deserialization weakness.

Is Commerce Cloud safe to use?

It depends on the version. The latest supported Commerce Cloud release clears the known issues; older versions may still be affected. Check the exact version you run for a verdict.

CVE data aggregated from NVD, CISA KEV and EPSS (FIRST.org). Related: Commerce Cloud security status · Commerce Cloud end-of-life · actively-exploited CVEs. Always verify against SAP's advisories — see our disclaimer.