Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.3

CVE-2026-76201: Adobe Commerce allows attacker to run scripts in users' browsers

CVE-2026-76201 · published 22 days ago
Summary

Adobe Commerce, including its B2B edition and the Magento Open Source version, contains a flaw that lets an attacker place malicious code in certain form fields. When a user later views the compromised page, the code runs in their browser and could hijack their session or account. Apply the vendor’s security update as soon as it is available and ensure all installations are kept current.

What to do
  • Update adobe commerce to version 2.4.4 or later.
  • Update adobe commerce_b2b to version 1.3.3 or later.
Affected software
VendorProductAffected versions
adobe adobe commerce <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
adobe adobe commerce b2b <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
adobe magento open source <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
adobe commerce < 2.4.4
2.4.4
2.4.5
2.4.6
2.4.7
2.4.8
2.4.9
cpe:2.3:a:adobe:commerce:*:*:*:*:*:*:*:*
adobe commerce_b2b < 1.3.3
1.3.3
1.3.4
1.4.2
1.5.2
1.5.3
cpe:2.3:a:adobe:commerce_b2b:*:*:*:*:*:*:*:*
adobe magento <= 2.4.6
2.4.7
2.4.8
2.4.9
cpe:2.3:a:adobe:magento:*:*:*:*:open_source:*:*:*
Original advisory text
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.3 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-79Cross-site Scripting (XSS)
Timeline
Published8 Sep 2026
Updated1 Oct 2026
First seen8 Sep 2026
Sources
CVE-2026-76201 · MITRE
Track software like this
Free during beta