← Back to CVE List
Vulnerability Intelligence Report
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

CVE-2026-76200

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Cross-Site Scripting (XSS) No Active Exploit Signals
CVSS Base Score
9.3
CRITICAL
Exploitability:2.9
Impact Score:5.8
Temporal Score:9.3
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-79 ↗Cross-site Scripting (Stored XSS) (CWE-79)

Affected Products & Versions

Vendor Product Affected Versions
Adobe Adobe Commerce 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug (affected), 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep (unaffected)
Adobe Adobe Commerce B2B 0 <= 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug (affected), 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep (unaffected)
Adobe Magento Open Source 0 <= 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug (affected), 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep (unaffected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Cross-Site Scripting (XSS)

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityAdobe Systems Incorporated · Vendor · USA
Reserved2026-08-19T11:09:52
Published2026-09-08T18:08:17
Patch Date2026-09-08
Last Updated2026-09-09T09:54:44

LINK COPIED TO CLIPBOARD