NCSC-2026-0292 [1.00] [M/H] Vulnerabilities patched in Adobe Commerce
Adobe has patched multiple vulnerabilities in Adobe Commerce. The vulnerabilities mainly involve incorrect authorization, allowing an attacker with various privilege levels to bypass security controls. This enables the attacker to obtain unauthorized read and write permissions without user interaction, gain access to sensitive data, and escalate privileges within the system. Additionally, there is a stored Cross-Site Scripting (XSS) vulnerability that allows low-privileged attackers to inject malicious JavaScript code into form fields. This code is executed in the browsers of victims, which can lead to unauthorized actions such as session hijacking and access to user accounts. Exploitation of these vulnerabilities can lead to changes in platform integrity, unauthorized access to resources and potential disruption of availability.
CSIRTS triage
- What
- Multiple vulnerabilities including incorrect authorization, stored XSS, and privilege escalation allow attackers to bypass security controls, access sensitive data, and manipulate platform integrity.
- Who is affected
- Adobe Commerce deployments across all privilege levels.
- Urgency
- High severity with authorization bypass and data access risks; apply patches immediately.
- Action
- Install patches for all seven CVEs (CVE-2026-48411 through CVE-2026-48416, CVE-2026-71362) from Adobe.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Commerce
Get an email when a new Commerce advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0292
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-484110.49% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484120.32% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 24% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484130.63% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 47% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484140.53% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 43% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484150.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-484160.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Moderate exploitation riskCVE-2026-713621.3% 30-day exploitation probability. Patch within normal cadence, watch for KEV listing. Riskier than 68% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48411 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48412 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48413 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48414 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48415 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48416 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-71362 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Adobe Magento: Multiple Vulnerabilitiescert-bund
- unknownMultiple vulnerabilities in Adobe products (August 13, 2026)cert-fr-avis
- criticalCVE-2026-71362: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- highCVE-2026-48416: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-48415: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-48414: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd
- highCVE-2026-48413: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd
- lowCVE-2026-48412: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- mediumCVE-2026-48411: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
Recent advisories for Adobe Commerce
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- criticalCVE-2026-71362: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd · 2026-08-11
- highCVE-2026-48416: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd · 2026-08-11
- highCVE-2026-48415: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd · 2026-08-11
- highCVE-2026-48414: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd · 2026-08-11
- highCVE-2026-48413: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd · 2026-08-11
- lowCVE-2026-48412: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd · 2026-08-11
More from NCSC-NL Advisories
- unknownNCSC-2026-0303 [1.01] [M/H] Vulnerabilities patched in GitLab by GitLab Inc.2026-08-25
- unknownNCSC-2026-0326 [1.00] [M/H] Vulnerabilities patched in Keycloak2026-08-25
- unknownNCSC-2026-0325 [1.00] [M/H] Vulnerabilities patched in Atlassian products2026-08-24
- unknownNCSC-2026-0324 [1.00] [M/H] Vulnerability fixed in Zimbra Collaboration Suite2026-08-23
- unknownNCSC-2026-0323 [1.00] [M/H] Vulnerabilities fixed in Cisco Secure Workload2026-08-21