ZeroHour

CVE-2026-76201

large

Stored XSS in Adobe Commerce and Magento Open Source lets attackers hijack sessions

CVSS 3.1
9.3 critical
EPSS
<1%p38
Published
()
Modified
AI analysis

Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by a stored cross-site scripting flaw (CWE-79) in which an attacker submits crafted content into a vulnerable form field and the malicious JavaScript later executes in any user's browser when they view the page containing that field. The attack vector requires no authentication (network vector, low complexity), but does require user interaction, and the changed scope means injected script can act beyond the vulnerable page, potentially giving the attacker elevated access or control over the victim's account or session. Any organization running an affected version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source is exposed, especially storefronts that allow unauthenticated form submissions and admin panels reached by privileged users. Exploitation status: no public proof-of-concept is known, the flaw is not listed in CISA KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is documented yet.

What to do: Apply the patched release referenced in Adobe's security bulletin for CVE-2026-76201 across all Adobe Commerce, Adobe Commerce B2B, and Magento Open Source deployments (exact patched versions are listed in the bulletin). Until patching, review content stored in storefront and admin form fields for unexpected scripts, and restrict/review admin access since stored XSS payloads may already be persisted. If compromise is suspected, rotate credentials for privileged accounts, as changed scope means admin sessions can be hijacked.

Affected
Adobe Commerce
Adobe Commerce B2B
adobe Magento (Magento Open Source)
Estimated exposure
largeon the order of 100,000+ live storefronts worldwide — Public web-technology surveys (e.g., W3Techs and BuiltWith) consistently rank Magento/Adobe Commerce among the top e-commerce platforms with roughly 10^5 live installations, and every deployment of the affected product line shares the same…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

Vendors
adobe
Products
commerce, commerce b2b, magento
Ecosystems
E-commerce
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.