Track vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.3
CVE-2026-76201: Adobe Commerce allows attacker to run scripts in users' browsers
CVE-2026-76201 · published 22 days ago
Summary
Adobe Commerce, including its B2B edition and the Magento Open Source version, contains a flaw that lets an attacker place malicious code in certain form fields. When a user later views the compromised page, the code runs in their browser and could hijack their session or account. Apply the vendor’s security update as soon as it is available and ensure all installations are kept current.
What to do
- Update adobe commerce to version 2.4.4 or later.
- Update adobe commerce_b2b to version 1.3.3 or later.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| adobe | adobe commerce | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug |
| adobe | adobe commerce b2b | <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug |
| adobe | magento open source | <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug |
| adobe | commerce |
< 2.4.4 2.4.4 2.4.5 2.4.6 2.4.7 2.4.8 2.4.9 cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:* |
| adobe | commerce_b2b |
< 1.3.3 1.3.3 1.3.4 1.4.2 1.5.2 1.5.3 cpe:2.3:a:adobe:commerce_b2b:*:*:*:*:*:*:*:* |
| adobe | magento |
<= 2.4.6 2.4.7 2.4.8 2.4.9 cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:* |
Original advisory text
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
References
- https://helpx.adobe.com/security/products/magento/apsb26-138.html Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/76xxx/CVE-2026-76201... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-76201 Vendor Advisory
Internet-facing
14 days
Internal
At next upgrade
- Not known to be exploited
- Needs hands-on effort to exploit
- Gives an attacker full control
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published8 Sep 2026
Updated1 Oct 2026
First seen8 Sep 2026
Track software like this
Free during beta