BlackTreeCVE IntelligenceAdobe · APSB26-138
Linked CVE review
Update Adobe Commerce to the fixed Adobe release
- Linked CVEs
- 9
- Confirmed exploited
- 1
- PoC or lab evidence
- 0
- Maximum CVSS
- 10.0
Confirmed exploitation, public exploit material, EPSS probability and CVSS severity answer different questions. “No confirmation recorded” means the checked sources do not currently confirm exploitation. It is not proof that exploitation has not occurred.
| CVE and description | Severity | Exploit reality | Forecast and access | Remediation |
|---|---|---|---|---|
CVE-2026-75650 Immediate evidence Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine VulnerabilityAdobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code. | 10.0 · CVSS 3.1 · CriticalSource: CNA | Confirmed in the wildCISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2026-09-08.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 3.95% · 90.1th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interaction | Patch nowCISA confirms exploitation in the wild and lists 2026-09-11 as the remediation due date.Patch available. Adobe Commerce: Hotfix for CVE-2026-7565; Adobe Commerce B2B: Hotfix for CVE-2026-7565; Magento Open Source: Hotfix for CVE-2026-7565 |
CVE-2026-77110 Scheduled assessment Adobe Commerce | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE-22)Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user inter | 7.6 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 1.09% · 64.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · HIGH privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
CVE-2026-77111 Scheduled assessment Adobe Commerce | Incorrect Authorization (CWE-863)Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed. | 8.7 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.84% · 56.5th percentileForecast date: 2026-10-05NETWORK · LOW complexity · HIGH privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
CVE-2026-77774 Scheduled assessment Adobe Commerce | Incorrect Authorization (CWE-863)Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. | 8.6 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.83% · 56.1th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
CVE-2026-77108 Scheduled assessment Adobe Commerce | Incorrect Authorization (CWE-863)Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. | 7.5 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.82% · 55.8th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. Adobe Commerce: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; Adobe Commerce B2B: 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; Magento Open Source: 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
CVE-2026-76200 Critical technical severity Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. | 9.3 · CVSS 3.1 · CriticalSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.74% · 53.2th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
CVE-2026-76201 Critical technical severity Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed. | 9.3 · CVSS 3.1 · CriticalSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.74% · 53.2th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · REQUIRED user interaction | Within 7 daysCritical technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
CVE-2026-77109 Scheduled assessment Adobe Commerce | Incorrect Authorization (CWE-863)Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed. | 8.6 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.69% · 51.1th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |
CVE-2026-76202 Scheduled assessment Adobe Commerce | Incorrect Authorization (CWE-863)Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction. | 8.2 · CVSS 3.1 · HighSource: CNA | No confirmation recordedNo CISA KEV match was present at the last successful refresh. This means no confirmation from that source, not proof of no exploitation.None recordedNo exploit-tagged reference or CISA SSVC proof-of-concept state is currently recorded. Research may still exist outside the structured feeds. | EPSS: 0.67% · 50.4th percentileForecast date: 2026-10-05NETWORK · LOW complexity · NONE privileges · NONE user interaction | Within 7 daysHigh technical severity; prioritise exposed affected systems while verifying vendor guidance.Patch available. 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep, 2.4.6-2026-sep, 2.4.5-2026-sep, 2.4.4-2026-sep; 1.5.3-2026-sep, 1.5.2-2026-sep, 1.4.2-2026-sep, 1.3.4-2026-sep, 1.3.3-2026-sep; 2.4.9-2026-sep, 2.4.8-2026-sep, 2.4.7-2026-sep |