Adobe Commerce
12 known vulnerabilities in Adobe Commerce, 6 critical, 4 actively exploited, with patch priority, exploit likelihood and the news covering them.
Recently exploited
- CVE-2026-75650 CVSS 10.0 critical · actively exploited Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- CVE-2026-71362 CVSS 9.1 critical · actively exploited Adobe Commerce and Magento Incorrect Authorization Vulnerability
- CVE-2025-54236 CVSS 9.1 critical · actively exploited Adobe Commerce and Magento Improper Input Validation Vulnerability
- CVE-2024-34102 CVSS 9.8 critical · actively exploited Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability
Latest vulnerabilities
- CVE-2026-77774 CVSS 8.6 high Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could…
- CVE-2026-77111 CVSS 8.7 high Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with…
- CVE-2026-77110 CVSS 7.6 high Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could…
- CVE-2026-77109 CVSS 8.6 high Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could…
- CVE-2026-77108 CVSS 7.5 high Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could…
- CVE-2026-76202 CVSS 8.2 high Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could…
- CVE-2026-76201 CVSS 9.3 critical Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious…
- CVE-2026-76200 CVSS 9.3 critical Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious…
- CVE-2026-75650 CVSS 10.0 critical · actively exploited Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
- CVE-2026-71362 CVSS 9.1 critical · actively exploited Adobe Commerce and Magento Incorrect Authorization Vulnerability
- CVE-2025-54236 CVSS 9.1 critical · actively exploited Adobe Commerce and Magento Improper Input Validation Vulnerability
- CVE-2024-34102 CVSS 9.8 critical · actively exploited Adobe Commerce and Magento Open Source Improper Restriction of XML External Entity Reference (XXE) Vulnerability