A recently discovered vulnerability, CVE-2026-58231, in SAP Commerce Cloud is being actively exploited in the wild, posing a significant threat to users. Additionally, threat actors are purchasing expired domains to deliver malware, while a macOS Screen Sharing flaw is being exploited to deploy Monero miners. A GeoServer zero-day vulnerability is also being probed, highlighting the ongoing cat-and-mouse game between attackers and defenders. Furthermore, Apple has warned hundreds of users of potential mercenary spyware attacks, underscoring the evolving nature of cyber threats. The exploitation status of CVE-2026-58231 is a key factor in determining the necessary response, with patching or monitoring being the primary considerations1. This matters to security practitioners because the active exploitation of vulnerabilities like CVE-2026-58231 demands prompt attention and action to prevent potential breaches.