CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

NCSC-2026-0292 [1.00] [M/H] Vulnerabilities patched in Adobe Commerce

unknownpublic exploitCVE-2026-48411CVE-2026-48412CVE-2026-48413CVE-2026-48414CVE-2026-48415CVE-2026-48416
Adobe has patched multiple vulnerabilities in Adobe Commerce. The vulnerabilities mainly involve incorrect authorization, allowing an attacker with various privilege levels to bypass security controls. This enables the attacker to obtain unauthorized read and write permissions without user interaction, gain access to sensitive data, and escalate privileges within the system. Additionally, there is a stored Cross-Site Scripting (XSS) vulnerability that allows low-privileged attackers to inject malicious JavaScript code into form fields. This code is executed in the browsers of victims, which can lead to unauthorized actions such as session hijacking and access to user accounts. Exploitation of these vulnerabilities can lead to changes in platform integrity, unauthorized access to resources and potential disruption of availability.

CSIRTS triage

What
Multiple vulnerabilities including incorrect authorization, stored XSS, and privilege escalation allow attackers to bypass security controls, access sensitive data, and manipulate platform integrity.
Who is affected
Adobe Commerce deployments across all privilege levels.
Urgency
High severity with authorization bypass and data access risks; apply patches immediately.
Action
Install patches for all seven CVEs (CVE-2026-48411 through CVE-2026-48416, CVE-2026-71362) from Adobe.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch Commerce

Get an email when a new Commerce advisory drops — max one per day, one-click unsubscribe.

Details

Source
NCSC-NL Advisories (NL · national-cert · site)
Severity
unknown
Published
2026-08-12
Exploitation
Not in CISA KEV at last sync
Language
Machine-translated to English — verify against the original

Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0292

Exploitation outlook

EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.

Referenced CVEs

CVECSIRTS overviewExternal
CVE-2026-48411coverage & exploitation statusNVD · CVE.org
CVE-2026-48412coverage & exploitation statusNVD · CVE.org
CVE-2026-48413coverage & exploitation statusNVD · CVE.org
CVE-2026-48414coverage & exploitation statusNVD · CVE.org
CVE-2026-48415coverage & exploitation statusNVD · CVE.org
CVE-2026-48416coverage & exploitation statusNVD · CVE.org
CVE-2026-71362coverage & exploitation statusNVD · CVE.org

Same CVEs, other sources

How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.

Recent advisories for Adobe Commerce

A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.

More from NCSC-NL Advisories