WHAT HAPPENED
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source,fixing several vulnerabilitiesthat could allow attackers to bypass security controls, gain higher privileges, and execute arbitrary code. The flaw could allow an unauthenticated remote attacker to escalate privileges without requiring administrator access. Adobe classified the vulnerability as critical because it could expose sensitive data and allow attackers to make unauthorized changes within affected commerce environments. Adobe Commerce VulnerabilitiesAdobe also addressed two critical stored cross-site scripting vulnerabilities, CVE-2026-48414 and CVE-2026-48413. Stored XSS vulnerabilities occur when an application saves malicious script content and later delivers it to other users through legitimate pages, forms, product information, customer records, or administrative interfaces.
Continue reading from the original publisher for the complete report and source context.
READ ORIGINAL STORY