Vulnerabilities & PatchesEmerging1 src
Critical Adobe Commerce Vulnerabilities Allows Hackers to Execute Arbitrary Code
Adobe has released an urgent security update for Adobe Commerce and Magento Open Source, fixing several vulnerabilities that could allow attackers to bypass security controls, gain higher privileges, and execute arbitrary code.
The most serious issue is CVE-2026-71362, an incorrect authorization vulnerability rated 9. 1 out of 10 under the CVSS scoring system. The flaw could allow an unauthenticated remote attacker to escalate privileges without requiring administrator access.
Adobe classified the vulnerability as critical because it could expose sensitive data and allow attackers to make unauthorized changes within affected commerce environments.
Adobe Commerce Vulnerabilities
Adobe also addressed two critical stored cross-site scripting vulnerabilities, CVE-2026-48414 and CVE-2026-48413. Both flaws may result in arbitrary code execution when exploited successfully.