CRITICAL 9.3 NVD
CVE-2026-76201
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Affected Products
- adobe/commerce
- adobe/commerce_b2b
- adobe/magento
References
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-08 via NVD. Affected: adobe/commerce, adobe/commerce_b2b, adobe/magento.
Risk Timeline
CVE Disclosed2026-09-08 · 2 days ago
Remediation Resources
Official Advisory
helpx.adobe.com/security/products/magento/apsb26-138.htmlRelated Vulnerabilities
| CVE | Title | Severity | CVSS |
|---|---|---|---|
| CVE-2026-75650 KEV | Adobe Commerce is affected by an Improper Neutralization of Special Elements Use | CRITICAL | 10.0 |
| CVE-2026-82004 | Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Specia | CRITICAL | 10.0 |
| CVE-2026-19232 | Adobe Experience Manager is affected by an Incorrect Authorization vulnerability | CRITICAL | 9.9 |
| CVE-2026-76200 | Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability | CRITICAL | 9.3 |
| CVE-2026-81996 | Acrobat Reader is affected by an Incorrect Authorization vulnerability that coul | HIGH | 8.8 |
| CVE-2026-77111 | Adobe Commerce is affected by an Incorrect Authorization vulnerability that coul | HIGH | 8.7 |
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.