Skip to content
AdobeCVE-2026-76201

Adobe Commerce: cross-site scripting

Critical9.3CVE-2026-76201 · Published Sep 8, 2026 · updated Sep 9, 2026

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Adobe advisory

Affected versions

PackageAffectedFixed in
Adobe Commerce
Product
<= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aNo fix yet
Adobe Commerce B2B
Product
<= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aNo fix yet
Magento Open Source
Product
<= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aNo fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-79

More Adobe advisories

All Adobe
Advisory
Adobe Acrobat 2024: heap buffer overflow
Medium5.5Sep 8
Adobe Acrobat 2024: prototype pollution
High8.2Sep 8
Adobe Acrobat 2024: improper authorization
High8.8Sep 8
Adobe Acrobat 2024: improper authorization
Medium6.3Sep 8
Adobe Acrobat 2024: resource exhaustion
Medium5.5Sep 8
Adobe Acrobat 2024: use after free
High7.8Sep 8

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.