Critical Adobe Commerce Vulnerabilities Allow Privilege Escalation and Code Execution
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, patching multiple critical vulnerabilities including privilege escalation and stored cross-site scripting flaws.

Adobe has issued an urgent security update, APSB26-92, for its Adobe Commerce and Magento Open Source platforms to address a series of critical vulnerabilities. These flaws could allow attackers to bypass security controls, escalate privileges, and execute arbitrary code on affected systems.
The most severe vulnerability, CVE-2026-71362, is an incorrect authorization flaw with a CVSS score of 9.1. This critical vulnerability could permit unauthenticated remote attackers to escalate their privileges without needing administrator access, potentially leading to unauthorized data access or system modifications.
In addition to the privilege escalation risk, Adobe has also patched two critical stored cross-site scripting (XSS) vulnerabilities: CVE-2026-48414 and CVE-2026-48413. These flaws, if successfully exploited, could enable arbitrary code execution. Stored XSS vulnerabilities occur when an application saves malicious scripts that are later delivered to other users through various means, such as product pages or administrative interfaces.
CVE-2026-48414 has a CVSS score of 7.7 and requires authentication, administrator privileges, user interaction, and high attack complexity. In contrast, CVE-2026-48413 is more accessible with a CVSS score of 8.7, requiring only a low-privileged authenticated account and user interaction, but not administrator privileges.
The update also addresses CVE-2026-48415, an incorrect authorization flaw affecting Adobe Commerce B2B deployments with a CVSS score of 7.6, which could allow an authenticated attacker without administrator privileges to bypass security features. Another authorization issue, CVE-2026-48416 (CVSS 7.5), could allow an unauthenticated attacker to bypass security controls. Furthermore, CVE-2026-48411 (CVSS 6.8) and CVE-2026-48412 (CVSS 2.7) address important authorization and moderate privilege escalation issues, respectively.
These vulnerabilities affect Adobe Commerce versions 2.4.4 through 2.4.9 (prior to the July 2026 security update) and Magento Open Source versions 2.4.6 through 2.4.9, along with multiple Adobe Commerce B2B releases. Adobe strongly recommends updating to the August 2026 releases as soon as possible to mitigate these risks.
While Adobe has stated it is unaware of any active exploitation of these vulnerabilities in the wild, the public disclosure of these flaws could increase their attractiveness to attackers, especially for internet-facing stores that remain unpatched. Administrators are advised to apply the necessary updates, review privileged accounts, monitor application logs for suspicious activity, and ensure web application firewall rules and access controls are properly configured.
This batch of vulnerabilities highlights the ongoing need for diligent patch management and security hygiene for e-commerce platforms, which are frequent targets for cybercriminals seeking to disrupt operations, steal sensitive data, or gain unauthorized access.