Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-76200: Adobe Commerce may run attacker scripts in form fields
CVE-2026-76200 · published 22 days ago
Summary
Adobe Commerce, including its B2B and Magento Open Source versions, allows attackers to place malicious code into certain form fields. When a user views the compromised page, the code can run in their browser and potentially take control of their account or session. Apply the latest security updates from Adobe as soon as possible to close the gap.
What to do
- Update adobe commerce to version 2.4.4 or later.
- Update adobe commerce_b2b to version 1.3.3 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | adobe commerce | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug |
| adobe | adobe commerce b2b | <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug |
| adobe | magento open source | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug |
| adobe | magento |
<= 2.4.6 2.4.7 2.4.8 2.4.9 cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:* |
| adobe | commerce |
< 2.4.4 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* |
| adobe | commerce_b2b |
< 1.3.3 1.3.3 1.3.4 1.4.2 1.5.2 1.5.3 cpe:2.3:a:adobe:commerce_b2b:*:*:*:*:*:*:*:* |
Original advisory text
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
References
- https://helpx.adobe.com/security/products/magento/apsb26-138.html Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76200... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-76200 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published8 Sep 2026
Updated1 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta