CRITICAL 9.3 NVD

CVE-2026-76201

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Affected Products

References

Published: 2026-09-08 · Source: NVD · Feed updated: 2026-09-11
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-09-08 via NVD. Affected: adobe/commerce, adobe/commerce_b2b, adobe/magento.

Risk Timeline

CVE Disclosed2026-09-08 · 2 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-75650 KEVAdobe Commerce is affected by an Improper Neutralization of Special Elements UseCRITICAL10.0
CVE-2026-82004Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of SpeciaCRITICAL10.0
CVE-2026-19232Adobe Experience Manager is affected by an Incorrect Authorization vulnerabilityCRITICAL9.9
CVE-2026-76200Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability CRITICAL9.3
CVE-2026-81996Acrobat Reader is affected by an Incorrect Authorization vulnerability that coulHIGH8.8
CVE-2026-77111Adobe Commerce is affected by an Incorrect Authorization vulnerability that coulHIGH8.7
vulnfeed aggregates 13138 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.