CVE-2026-48358 – Adobe Commerce and Experience Manager
“These critical weaknesses can turn trusted web platforms into a path for code execution and data exposure.”
Adobe has released updates addressing four critical vulnerabilities across Adobe Commerce and Adobe Experience Manager. CVE-2026-48356 allows dangerous file uploads that could lead to arbitrary code execution after user interaction. CVE-2026-48358 could allow arbitrary code execution without user interaction. CVE-2026-48356 has a CVSS score of 9.6, which is Critical severity. CVE-2026-48358 has a CVSS score of 9.1, which is Critical severity.
CVE-2026-48259 is a server-side request forgery vulnerability that could enable unauthorized server requests and code execution. CVE-2026-48359 is an XML external entity vulnerability that could expose sensitive files and lead to code execution. Both require low privileges but no user interaction. CVE-2026-48259 and CVE-2026-48359 each have a CVSS score of 9.6, which is Critical severity. No active exploitation is confirmed.
Key Details
- Affected Product
- Adobe Commerce
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- High
- User Interaction
- None
- CWE Classification
- CWE-116