Cyber & AI intelligence
Wasteland.
Briefs indexed2597
Issues28
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-76201 2026-09-08

CVE-2026-76201: Critical Stored XSS in Adobe Commerce and Magento Open Source

"Adobe has patched a critical stored cross-site scripting flaw (CVSS 9.3) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an unauthenticated attacker to inject malicious JavaScript into form…"

Adobe has patched a critical stored cross-site scripting flaw (CVSS 9.3) in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source that allows an unauthenticated attacker to inject malicious JavaScript into form fields and hijack the sessions of users who later view the affected page.

What Is It

CVE-2026-76201 is a stored cross-site scripting vulnerability (CWE-79) in Adobe Commerce. An attacker can inject malicious scripts into vulnerable form fields. That JavaScript is then executed in a victim's browser when they browse to the page containing the field, potentially giving the attacker elevated access or control over the victim's account or session.

Adobe's PSIRT rates the issue CVSS 3.1 base score 9.3 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N. Notably, the scope is changed, no privileges are required, and attack complexity is low; the only barrier is that a victim must visit the poisoned page.

Why It Matters

The vulnerability is network-reachable, requires no authentication, has low attack complexity, and carries high impact to both confidentiality and integrity. Because the payload is stored rather than reflected, an attacker does not need to phish a target with a crafted link; they plant it once and wait for admins or customers to load the page. Account and session takeover is the stated outcome.

CVE-2026-76201 is not listed in the CISA Known Exploited Vulnerabilities catalog as of 2026-09-08, so there is no confirmation of active exploitation at this time.

What's Vulnerable

Patch Status

Fixed builds are available. Adobe lists the 2026-sep patch level as unaffected across all three products: Adobe Commerce 2.4.9/2.4.8/2.4.7/2.4.6/2.4.5/2.4.4-2026-sep, Adobe Commerce B2B 1.5.3/1.5.2/1.4.2/1.3.4/1.3.3-2026-sep, and Magento Open Source 2.4.9/2.4.8/2.4.7-2026-sep. Note that Magento Open Source 2.4.6 has an affected entry but no listed 2026-sep fixed version; operators on that branch should consult Adobe's advisory directly.

The CVE was published 2026-09-08 and NVD analysis is still in progress, so enrichment data such as CPEs may change.

Sources