CVE-2026-48359 – Adobe Commerce and Experience Manager

CVSS 9.6 CRITICAL Critical - Same Day Deployment

“These critical weaknesses can turn trusted web platforms into a path for code execution and data exposure.”

Adobe has released updates addressing four critical vulnerabilities across Adobe Commerce and Adobe Experience Manager. CVE-2026-48356 allows dangerous file uploads that could lead to arbitrary code execution after user interaction. CVE-2026-48358 could allow arbitrary code execution without user interaction. CVE-2026-48356 has a CVSS score of 9.6, which is Critical severity. CVE-2026-48358 has a CVSS score of 9.1, which is Critical severity.

CVE-2026-48259 is a server-side request forgery vulnerability that could enable unauthorized server requests and code execution. CVE-2026-48359 is an XML external entity vulnerability that could expose sensitive files and lead to code execution. Both require low privileges but no user interaction. CVE-2026-48259 and CVE-2026-48359 each have a CVSS score of 9.6, which is Critical severity. No active exploitation is confirmed.

Key Details

Affected Product
Adobe Experience Manager
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
CWE Classification
CWE-611
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.