CVE-2026-47996 – Adobe Commerce
“A handful of weaknesses across one platform can quickly become a complete compromise if left unpatched.”
Adobe Commerce addresses eight security vulnerabilities affecting file uploads, output encoding, authorization, cross-site scripting (XSS), and SQL injection. The most severe issues could lead to arbitrary code execution, while others allow security feature bypasses, unauthorized access, or malicious script injection that could compromise user accounts or sessions.
CVE-2026-48356 has a CVSS score of 9.6, Critical severity. CVE-2026-48358 has a CVSS score of 9.1, Critical severity. CVE-2026-47984 has a CVSS score of 8.2, High severity. CVE-2026-47988 has a CVSS score of 8.6, High severity. CVE-2026-47994 has a CVSS score of 8.7, High severity. CVE-2026-47995 has a CVSS score of 8.1, High severity. CVE-2026-47992 has a CVSS score of 7.2, High severity. CVE-2026-47996 has a CVSS score of 7.6, High severity. Based on the information provided, there is no verified public exploitation or proof-of-concept associated with these vulnerabilities.
Key Details
- Affected Product
- Adobe Commerce
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-863