Adobe has patched a critical stored cross-site scripting flaw (CVSS 9.3) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an unauthenticated attacker to inject malicious JavaScript into form fields and hijack the sessions of users who later view the affected page.
What Is It
CVE-2026-76201 is a stored cross-site scripting vulnerability (CWE-79) in Adobe Commerce. An attacker can inject malicious scripts into vulnerable form fields. That JavaScript is then executed in a victim's browser when they browse to the page containing the field, potentially giving the attacker elevated access or control over the victim's account or session.
Adobe's PSIRT rates the issue CVSS 3.1 base score 9.3 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. Notably, the scope is changed, no privileges are required, and attack complexity is low; the only barrier is that a victim must visit the poisoned page.
Why It Matters
The vulnerability is network-reachable, requires no authentication, has low attack complexity, and carries high impact to both confidentiality and integrity. Because the payload is stored rather than reflected, an attacker does not need to phish a target with a crafted link; they plant it once and wait for admins or customers to load the page. Account and session takeover is the stated outcome.
CVE-2026-76201 is not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-08, so there is no confirmation of active exploitation at this time.
What's Vulnerable
- Adobe Commerce: 2.4.9, 2.4.8, 2.4.7, 2.4.6, 2.4.5, and 2.4.4 at the
2026-augpatch level and earlier. - Adobe Commerce B2B: 1.5.3, 1.5.2, 1.4.2, 1.3.4, and 1.3.3 at the
2026-augpatch level and earlier. - Magento Open Source: 2.4.9, 2.4.8, 2.4.7, and 2.4.6 at the
2026-augpatch level and earlier.
Patch Status
Fixed builds are available. Adobe lists the 2026-sep patch level as unaffected across all three products: Adobe Commerce 2.4.9/2.4.8/2.4.7/2.4.6/2.4.5/2.4.4-2026-sep, Adobe Commerce B2B 1.5.3/1.5.2/1.4.2/1.3.4/1.3.3-2026-sep, and Magento Open Source 2.4.9/2.4.8/2.4.7-2026-sep. Note that Magento Open Source 2.4.6 has an affected entry but no listed 2026-sep fixed version; operators on that branch should consult Adobe's advisory directly.
The CVE was published 2026-09-08 and NVD analysis is still in progress, so enrichment data such as CPEs may change.
Sources
- Adobe Security Bulletin APSB26-138; https://helpx.adobe.com/security/products/magento/apsb26-138.html
- NVD, CVE-2026-76201, https://nvd.nist.gov/vuln/detail/CVE-2026-76201
- CISA Known Exploited Vulnerabilities Catalog; https://www.cisa.gov/known-exploited-vulnerabilities-catalog