NCSC-2026-0361 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Commerce
Adobe heeft meerdere kwetsbaarheden verholpen in Adobe Commerce. De kwetsbaarheden betreffen onder andere stored Cross-Site Scripting (XSS) waarbij aanvallers kwaadaardige JavaScript-code kunnen injecteren in formulier velden binnen de applicatie. Deze code wordt uitgevoerd in de context van de browser van het slachtoffer en kan ongeautoriseerde acties uitvoeren, zoals het kapen van sessies of het escaleren van privileges. Daarnaast zijn er meerdere incorrecte autorisatieproblemen geïdentificeerd die het mogelijk maken voor aanvallers om hun privileges binnen het systeem te verhogen, ongeautoriseerde toegang te verkrijgen tot gevoelige informatie, en beveiligingscontroles te omzeilen zonder dat gebruikersinteractie nodig is. Verder is er een path traversal kwetsbaarheid die aanvallers met hoge privileges in staat stelt om beveiligingsmechanismen te omzeilen en toegang te krijgen tot bestanden of mappen buiten de bedoelde scope. Sommige van deze kwetsbaarheden kunnen leiden tot beperkte verstoring van de beschikbaarheid van diensten. Alle genoemde kwetsbaarheden zijn specifiek voor Adobe Commerce en kunnen door kwaadwillenden op afstand worden misbruikt.
Details
Original advisory: https://advisories.ncsc.nl/advisory?id=NCSC-2026-0361
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-762000.76% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762010.76% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 53% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-762020.39% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 33% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771080.48% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771090.41% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 34% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771100.78% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 54% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-771110.51% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 42% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-777740.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 41% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-76200 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76201 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-76202 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77108 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77109 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77110 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77111 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-77774 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- highexploited[NEU] [hoch] Adobe Magento: Mehrere Schwachstellencert-bund
- unknownMultiples vulnérabilités dans les produits Adobe (09 septembre 2026)cert-fr-avis
- highCVE-2026-77774: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-77111: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a …nvd
- highCVE-2026-77110: Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory (…nvd
- highCVE-2026-77109: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- highCVE-2026-77108: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- highCVE-2026-76202: Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in pr…nvd
- criticalCVE-2026-76201: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd
- criticalCVE-2026-76200: Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be …nvd
More from NCSC-NL Advisories
- unknownNCSC-2026-0365 [1.00] [H/H] Kwetsbaarheden verholpen in Check Point VPN producten2026-09-10
- unknownNCSC-2026-0364 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Illustrator2026-09-09
- unknownNCSC-2026-0363 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Experience Manager2026-09-09
- unknownNCSC-2026-0362 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe ColdFusion2026-09-09
- unknownNCSC-2026-0360 [1.00] [M/H] Kwetsbaarheden verholpen in Adobe Photoshop Desktop2026-09-09