CVE-2026-47995 – Adobe Commerce

CVSS 8.1 IMPORTANT Critical - Same Day Deployment

“A handful of weaknesses across one platform can quickly become a complete compromise if left unpatched.”

Adobe Commerce addresses eight security vulnerabilities affecting file uploads, output encoding, authorization, cross-site scripting (XSS), and SQL injection. The most severe issues could lead to arbitrary code execution, while others allow security feature bypasses, unauthorized access, or malicious script injection that could compromise user accounts or sessions.

CVE-2026-48356 has a CVSS score of 9.6, Critical severity. CVE-2026-48358 has a CVSS score of 9.1, Critical severity. CVE-2026-47984 has a CVSS score of 8.2, High severity. CVE-2026-47988 has a CVSS score of 8.6, High severity. CVE-2026-47994 has a CVSS score of 8.7, High severity. CVE-2026-47995 has a CVSS score of 8.1, High severity. CVE-2026-47992 has a CVSS score of 7.2, High severity. CVE-2026-47996 has a CVSS score of 7.6, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.

Key Details

Affected Product
Adobe Commerce
Attack Vector
Network
Attack Complexity
Low
Privileges Required
High
User Interaction
Required
CWE Classification
CWE-79
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.