ZeroHour

Vulnerabilities

9 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-48273
Eval Injection RCE in Adobe ColdFusion (CVSS 9.9, low-privileged attacker)

CVE-2026-48273 is a critical (CVSS 9.9) eval injection flaw (CWE-95) in Adobe ColdFusion in which untrusted input is not properly neutralized before it is placed into dynamically evaluated code. A remote attacker who has only low-privileged access to a vulnerable ColdFusion server can trigger the flaw over the network, with no user interaction required. Successful exploitation yields arbitrary code execution in the context of the current user, and the changed CVSS scope (S:C) indicates the impact can extend beyond the directly vulnerable component, a pattern typical of ColdFusion flaws that enable broader system-level code execution. All Adobe ColdFusion deployments are potentially affected; the source data does not specify affected version ranges, so admins should consult Adobe's bulletin for the exact versions fixed. As of this writing there is no known public proof-of-concept and the flaw is not in CISA KEV, though EPSS assigns a 1.7% probability of exploitation within 30 days; the fix shipped in Adobe's large recent patch batch, which also addressed three CVSS 10.0 ColdFusion and Campaign Classic flaws.

Do: Apply the Adobe ColdFusion security update covering this CVE from the current patch batch immediately on all ColdFusion servers, prioritizing any that are internet-exposed, and confirm your exact version against Adobe's bulletin since fixed versions are not listed here. Because only low-privileged access is required and no user interaction is needed, audit which accounts and request paths feed untrusted input into dynamically evaluated expressions and restrict or validate such inputs. No public PoC or known exploitation exists yet, so monitor Adobe advisories and threat feeds for updated indicators of compromise.

9.92%
  • Adobe ColdFusion
large~tens of thousands of internet-exposed ColdFusion servers (estimate; Adobe does not publish install counts)
CVE-2026-19232
Incorrect Authorization in Adobe Experience Manager Enables Arbitrary Code Execution

CVE-2026-19232 is an incorrect authorization flaw (CWE-863) in Adobe Experience Manager (AEM) in which permission checks are not properly enforced, letting requests reach functionality a low-privileged user should not be able to invoke. It is triggered over the network by an authenticated low-privileged attacker, requires no user interaction, and carries a changed scope (S:C), meaning the impact can extend beyond the vulnerable component into the broader AEM instance. A successful attacker gains arbitrary code execution in the context of the current user and can potentially obtain elevated access or control over the victim's account or session, with confidentiality, integrity, and availability impacts all rated high (CVSS 3.1: 9.9 critical). Any organization running an affected version of AEM is exposed; the available data does not specify affected version ranges, so defenders should consult Adobe's security bulletin for exact versions. There is no evidence of active exploitation so far: the flaw is not in CISA KEV, no public proof-of-concept is known, and EPSS estimates only a ~0.6% probability of exploitation in the next 30 days (45th percentile).

Do: Check Adobe's security bulletin (CNA: [email protected]) for the affected AEM version ranges and apply the patched release as soon as it is identified, treating this as a critical-priority patch given the 9.9 CVSS score. Until patched, restrict network access to AEM author and publish instances, review and tighten permissions granted to low-privileged users, and monitor logs for anomalous session activity or account-takeover indicators. No public PoC or known in-the-wild exploitation exists today, but the severity and changed scope warrant prompt remediation.

9.9<1%
  • Adobe Experience Manager
large≈ tens of thousands of deployed/internet-exposed AEM instances (estimated)
CVE-2026-82004
Unauthenticated OS Command Injection in Adobe Campaign Classic

Adobe Campaign Classic (ACC) contains an OS command injection flaw (CWE-78) in which special elements passed to an operating system command are improperly neutralized, allowing attacker-supplied commands to run on the host. Per the CVSS vector, it is reachable over the network (AV:N), requires no privileges or user interaction, and has changed scope (S:C), meaning a successful attack can also affect resources beyond the vulnerable component. An attacker gains arbitrary code execution in the context of the current user, with high impact to confidentiality, integrity, and availability. Any organization running an affected Adobe Campaign Classic deployment is potentially exposed, though only instances reachable over the network are practically exploitable. No public proof-of-concept or confirmed in-the-wild exploitation is known, EPSS estimates a ~1.4% probability of exploitation within 30 days, and the fix arrived in a large Adobe patch release covering 170+ vulnerabilities.

Do: Upgrade Campaign Classic to the fixed build listed in Adobe's security bulletin for this CVE, since the affected and fixed version numbers are not included in the data provided. Until patched, limit network exposure of Campaign Classic application/web servers to trusted networks, as the flaw is exploitable without authentication or user interaction. Monitor for a public PoC or CISA KEV listing and review application service accounts for signs of unexpected command execution.

10.01%
  • Adobe Campaign Classic (ACC)
moderate~1,000-10,000 enterprise deployments worldwide (estimate; Adobe publishes no install counts)
CVE-2026-76201
Stored XSS in Adobe Commerce and Magento Open Source lets attackers hijack sessions

Adobe Commerce, Adobe Commerce B2B, and Magento Open Source are affected by a stored cross-site scripting flaw (CWE-79) in which an attacker submits crafted content into a vulnerable form field and the malicious JavaScript later executes in any user's browser when they view the page containing that field. The attack vector requires no authentication (network vector, low complexity), but does require user interaction, and the changed scope means injected script can act beyond the vulnerable page, potentially giving the attacker elevated access or control over the victim's account or session. Any organization running an affected version of Adobe Commerce, Adobe Commerce B2B, or Magento Open Source is exposed, especially storefronts that allow unauthenticated form submissions and admin panels reached by privileged users. Exploitation status: no public proof-of-concept is known, the flaw is not listed in CISA KEV, and EPSS estimates only a 0.8% probability of exploitation within 30 days, so no confirmed in-the-wild exploitation is documented yet.

Do: Apply the patched release referenced in Adobe's security bulletin for CVE-2026-76201 across all Adobe Commerce, Adobe Commerce B2B, and Magento Open Source deployments (exact patched versions are listed in the bulletin). Until patching, review content stored in storefront and admin form fields for unexpected scripts, and restrict/review admin access since stored XSS payloads may already be persisted. If compromise is suspected, rotate credentials for privileged accounts, as changed scope means admin sessions can be hijacked.

9.3<1%
  • Adobe Commerce
  • Adobe Commerce B2B
  • adobe Magento (Magento Open Source)
largeon the order of 100,000+ live storefronts worldwide
CVE-2026-76200
Stored XSS in Adobe Commerce (Magento) Can Hijack Admin and Customer Sessions

CVE-2026-76200 is a stored Cross-Site Scripting (CWE-79) flaw in Adobe Commerce that lets an attacker persist malicious JavaScript in vulnerable form fields. When a victim later browses to a page containing the injected field, the script executes in their browser with the CVSS scope-change (S:C) indicating the impact crosses component boundaries, such as reaching an admin or another user's session. An attacker who succeeds can gain elevated access or control over the victim's account or session, which on an e-commerce platform could mean admin panel access or compromise of customer accounts. Affected products are Adobe Commerce, Magento, and the Commerce B2B offering, with specific affected and fixed version ranges not stated in the available data. Exploitation has not been confirmed: there is no known public proof-of-concept, the flaw is not in CISA KEV, and EPSS estimates only a 0.8% chance of exploitation within 30 days.

Do: Patch by upgrading to the release specified in Adobe's security bulletin for this CVE, prioritizing stores with internet-exposed account or checkout forms where the vulnerable fields can be populated. Until patched, restrict and sanitize input to the affected form fields and review recent admin/customer session activity for signs of hijacking. Because scope is 'changed', assume a successful injection could compromise higher-privileged sessions than the field's own context, so validate any admin accounts that interacted with attacker-modified content.

9.3<1%
  • Adobe Commerce
  • Adobe Magento
  • Adobe Commerce B2B
largeorder of tens of thousands of live stores (≈50,000–150,000 Magento/Adobe Commerce deployments)
CVE-2026-75650
Unauthenticated Template Injection RCE in Adobe Commerce and Magento (CVE-2026-75650)

Adobe Commerce and Magento (including Adobe Commerce B2B) contain an improper neutralization of special elements used in a template engine (CWE-1336), a template-injection flaw that permits arbitrary code execution in the context of the current user. The flaw is reachable over the network by unauthenticated attackers, requires no user interaction, and its changed scope (CVSS 3.1 S:C) means injected code executes beyond the vulnerable component, producing a maximum-severity (CVSS 10.0) remote code execution condition. A successful attacker gains arbitrary code execution on the storefront server; in the observed campaign, intruders installed a Rust backdoor and a PHP web shell (dubbed 'StyleSmuggler') on compromised servers. Any organization running an Adobe Commerce, Adobe Commerce B2B, or Magento storefront is in scope, with internet-facing e-commerce deployments most exposed. Exploitation is confirmed in the wild: the bug was abused as a zero-day before patching and was added to CISA's Known Exploited Vulnerabilities catalog on 2026-09-08.

Do: Apply Adobe's released patches immediately per vendor instructions, prioritizing internet-facing Commerce/Magento storefronts, and ensure compliance with CISA BOD 26-04 timelines for KEV entries. Hunt for 'StyleSmuggler' indicators of compromise, including unexpected Rust backdoor binaries and PHP web shells on hosts, and review template/theme customizations for tampering. Exact fixed version numbers are not included in the available data, so consult Adobe's advisory for the correct patched release for your Commerce/Magento version line.

10.02% KEV PoC
  • Adobe Commerce
  • Adobe Commerce B2B
  • Adobe Magento (open-source)
massroughly 100,000-300,000 internet-facing storefronts
CVE-2026-76197
+2 in the same advisory: …76195 …76193
Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that cou

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

NVD description · AI analysis pending
10.02%
  • adobe campaign