Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Cybersecurity NewsArchived Aug 13, 2026✓ Full text saved
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute arbitrary code. The most serious issue is CVE-2026-71362, an incorrect authorization vulnerability rated 9.1 out of 10 under the CVSS scoring system. The flaw could […] The post Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code appeared first on Cyber Secur
Full text archived locally
✦ AI Summary· Claude Sonnet
HomeAdobe
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
By Abinaya
August 13, 2026
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute arbitrary code.
The most serious issue is CVE-2026-71362, an incorrect authorization vulnerability rated 9.1 out of 10 under the CVSS scoring system. The flaw could allow an unauthenticated remote attacker to escalate privileges without requiring administrator access.
Adobe classified the vulnerability as critical because it could expose sensitive data and allow attackers to make unauthorized changes within affected commerce environments.
Adobe Commerce Vulnerabilities
Adobe also addressed two critical stored cross-site scripting vulnerabilities, CVE-2026-48414 and CVE-2026-48413. Both flaws may result in arbitrary code execution when exploited successfully.
Stored XSS vulnerabilities occur when an application saves malicious script content and later delivers it to other users through legitimate pages, forms, product information, customer records, or administrative interfaces.
CVE-2026-48414 has a CVSS score of 7.7 and requires authentication, administrator privileges, user interaction, and high attack complexity. CVE-2026-48413 is more accessible, with a CVSS score of 8.7.
It requires a low-privileged authenticated account and user interaction, but does not require administrator privileges. The update, tracked as APSB26-92, was published on August 11, 2026, with a priority rating of 2.
In a real attack, a threat actor may attempt to use a compromised customer, employee, or partner account to inject malicious content into a commerce platform.
Another critical vulnerability, CVE-2026-48415, affects Adobe Commerce B2B deployments. The incorrect authorization flaw could enable an authenticated attacker without administrator privileges to bypass security features.
Adobe assigned it a CVSS score of 7.6. CVE-2026-48416 is also an authorization issue, rated 7.5, that may allow an unauthenticated attacker to bypass security controls.
The update additionally fixes CVE-2026-48411, an important authorization flaw with a CVSS score of 6.8, and CVE-2026-48412, a moderate privilege-escalation issue rated 2.7.
Although these vulnerabilities have lower severity ratings, organizations should treat the update as a complete security package rather than selectively addressing only the critical bugs.
Affected products include Adobe Commerce versions 2.4.4 through 2.4.9 with the July 2026 security update or earlier, Magento Open Source versions 2.4.6 through 2.4.9, and multiple Adobe Commerce B2B releases. Adobe recommends updating to the August 2026 releases as soon as possible.
Adobe stated that it is not aware of active exploitation of these vulnerabilities in the wild. However, public security advisories can increase attacker interest, particularly where internet-facing stores remain unpatched.
Administrators should apply the relevant August 2026 update, review privileged accounts, monitor application logs for unusual activity, and validate that web application firewall rules and access controls are functioning correctly.
Strengthen Your SOC by Accelerating Threat Detection & Rapid Investigations. -> Integrate ANY.RUN With Your SOC Now.
Tags
cyber security
cyber security news
Copy URL
Linkedin
Twitter
ReddIt
Telegram
Abinayahttps://cybersecuritynews.com/
Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.
Cyber Security Guide
Top 10 Malware Threats of the Week – AsyncRAT, Remcos, and Xworm Lead the Surge
Three PhaaS Kits Targeting US Organizations to Steal M65 Logins by Bypassing MFA
How Top SOCs Detect and Stop AI Phishing that Beats Email Gateways
Top 10 Phishing Kits Used by Hackers to Launch Cyberattacks (July 20-26, 2026)
An SOC Story of Why Fast Answers Beat Perfect Answers in Cyber Incident Response
Latest Cyber News
Cyber Security
Critical WordPress RCE Vulnerability Allows Authors to Execute Code via Malicious PNG File
Cyber Security News
Palo Alto Networks Patches 11 New Vulnerabilities Across PAN-OS, GlobalProtect, and Prisma Access
Cyber Attack News
New “City-Forum” Hackers Attacking Salesforce and ServiceNow Instances Worldwide
Cyber Security Funding
Mindgard Raises $30 Million to Tackle AI’s Fastest-Growing Attack Surface
Cyber Security News
China-linked Hackers Using AI Agents to Attack Taiwan Government Websites
Expert Talks
Expert Talks
From Reactive Forensics to Predictive Defence: Strengthening Cyber Resilience in Banking
Expert Talks
Beyond the Lure: What the DoNot Campaign Reveals About Modern Cyber Espionage
Expert Talks
Your Incident Response Plan Has a Dependency You Never Approved
Expert Talks
Security in the AI Era Starts with First Principles
Cyber Security News
Planning Your AI Security – How will You Manage All Your Resources?