September 2026 Patch TuesdayAPSB26-138Normal patch window

Adobe · APSB26-138

Linked CVE review

Update Adobe Commerce to the fixed Adobe release

Linked CVEs
9
Confirmed exploited
1
PoC or lab evidence
0
Maximum CVSS
10.0
Evidence is kept separate

Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.

Reset
9 of 9 linked CVEs shown
Confirmed exploitedCVSS above 9.0
CVE and descriptionSeverityExploit realityForecast and accessRemediation
CVE-2026-75650 Immediate evidence
Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

10.0 · CVSS 3.1 · CriticalSource: CNAConfirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-09-08.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 3.95% · 90.1th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interactionPatch nowCISA confirms exploitation in the wild and lists 2026-09-11 as the remediation due date.Patch available. Adobe Commerce: Hotfix for CVE-2026-7565; Adobe Commerce B2B: Hotfix for CVE-2026-7565; Magento Open Source: Hotfix for CVE-2026-7565
CVE-2026-77110 Scheduled assessment
Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)

Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user inter

7.6 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 1.09% · 64.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · HIGH privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
CVE-2026-77111 Scheduled assessment
Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.

8.7 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.84% · 56.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · HIGH privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
CVE-2026-77774 Scheduled assessment
Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed.

8.6 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.83% · 56.1th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
CVE-2026-77108 Scheduled assessment
Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

7.5 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.82% · 55.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. Adobe Commerce: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; Adobe Commerce B2B: 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; Magento Open Source: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
CVE-2026-76200 Critical technical severity
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

9.3 · CVSS 3.1 · CriticalSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.74% · 53.2th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
CVE-2026-76201 Critical technical severity
Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

9.3 · CVSS 3.1 · CriticalSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.74% · 53.2th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · REQUIRED user interactionWithin 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
CVE-2026-77109 Scheduled assessment
Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.

8.6 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.69% · 51.1th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep
CVE-2026-76202 Scheduled assessment
Adobe Commerce | Incorrect Authorization (CWE-863)

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.

8.2 · CVSS 3.1 · HighSource: CNANo confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds.EPSS: 0.67% · 50.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interactionWithin 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep