CVE-2026-34648
massUnauthenticated Resource-Exhaustion DoS in Adobe Commerce and Magento
Adobe Commerce and Magento Open Source are affected by an uncontrolled resource consumption flaw (CWE-400) that allows an unauthenticated remote attacker to exhaust system resources and cause an application denial-of-service. The flaw is reachable over the network with no privileges and no user interaction, per the CVSS vector (AV:N/AC:L/PR:N/UI:N), and yields high availability impact with no confidentiality or integrity impact. Attackers can trigger it directly against internet-facing storefronts, degrading or taking the shop offline. It affects Adobe Commerce, Adobe Commerce B2B, and Magento across the 2.4.4 through 2.4.9 release lines up to the patch levels listed in the advisory (2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, 2.4.9-beta1 and earlier). No exploitation is confirmed in the wild and no public proof-of-concept is known, but the 22.6% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within the next 30 days.
What to do: Upgrade every affected 2.4.x line to the first patched release beyond the listed patch levels (i.e., past 2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, and 2.4.8-p4, and move off 2.4.9-beta1) per Adobe's security bulletin, and verify installed versions via composer/composer.lock. Until patched, apply rate limiting or WAF throttling on unauthenticated storefront endpoints and monitor CPU/memory for resource-exhaustion patterns. Given the 98th-percentile EPSS, prioritize this patch in the next maintenance window.
| Adobe Commerce | 2.4.9-beta1 and earlier (2.4.9 line); 2.4.8 through 2.4.8-p4; 2.4.7 through 2.4.7-p9; 2.4.6 through 2.4.6-p14; 2.4.5 through 2.4.5-p16; 2.4.4 through 2.4.4-p17 |
| Adobe Commerce B2B | 2.4.x lines listed for Adobe Commerce per the Adobe CPE (2.4.4-p17, 2.4.5-p16, 2.4.6-p14, 2.4.7-p9, 2.4.8-p4, 2.4.9-beta1 and earlier) |
| Adobe Magento (Open Source) | 2.4.9-beta1 and earlier (2.4.9 line); 2.4.8 through 2.4.8-p4; 2.4.7 through 2.4.7-p9; 2.4.6 through 2.4.6-p14; 2.4.5 through 2.4.5-p16; 2.4.4 through 2.4.4-p17 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability to exhaust system resources, resulting in an application denial-of-service condition. Exploitation of this issue does not require user interaction.
- Vendors
- adobe
- Products
- commerce, commerce b2b, magento
- Ecosystems
- E-commerce
- Weakness
- CWE-400
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.