Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Trump Authorizes Private Firms for Cyber Operations Against Foreign Criminals
August 13, 2026
Critical Adobe Commerce Flaws Let Attackers Execute Code (CVE-2024-20724, CVE-2024-20725)
August 13, 2026
Cisco ASA, FTD Critical 0-Day Lets Attackers Trigger DoS
August 13, 2026
Home/CyberSecurity News/Critical Adobe Commerce Flaws Let Attackers Execute Code (CVE-2024-20724, CVE-2024-20725)
CyberSecurity News

Critical Adobe Commerce Flaws Let Attackers Execute Code (CVE-2024-20724, CVE-2024-20725)

Key Takeaways Adobe has released an urgent security update for critical vulnerabilities in Adobe Commerce and Magento Open Source. The most severe flaw, CVE-2026-71362, is an authorization bypass...

David kimber
David kimber
August 13, 2026 3 Min Read
3 0

Key Takeaways

  • Adobe has released an urgent security update for critical vulnerabilities in Adobe Commerce and Magento Open Source.
  • The most severe flaw, CVE-2026-71362, is an authorization bypass allowing unauthenticated attackers to escalate privileges with a CVSS score of 9.1.
  • Multiple other vulnerabilities, including critical stored cross-site scripting (XSS) and authorization bypasses, could lead to arbitrary code execution or security feature circumvention.
  • Affected versions include Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9.
  • Patches were released on August 11, 2026, and immediate application is strongly recommended.

Adobe has issued a critical security bulletin addressing several serious vulnerabilities within its Adobe Commerce and Magento Open Source platforms. These flaws, if exploited, could allow malicious actors to bypass security measures, achieve elevated privileges, and execute arbitrary code on affected systems.

Table Of Content

  • Key Takeaways
  • Adobe Commerce Vulnerabilities Detailed
  • Critical Stored Cross-Site Scripting (XSS) Flaws
  • Additional Authorization Bypass Vulnerabilities
  • What You Should Do

The most significant vulnerability identified is CVE-2026-71362, an authorization bypass with a CVSS score of 9.1, categorizing it as critical. This flaw enables an unauthenticated attacker to remotely escalate privileges without requiring administrative access. Adobe highlighted the severity of this issue, noting its potential to expose sensitive data and facilitate unauthorized modifications within compromised commerce environments.

Adobe Commerce Vulnerabilities Detailed

Critical Stored Cross-Site Scripting (XSS) Flaws

Among the patched issues are two critical stored cross-site scripting (XSS) vulnerabilities, CVE-2026-48414 and CVE-2026-48413. Successful exploitation of either of these could lead to arbitrary code execution.

Stored XSS vulnerabilities arise when an application fails to properly sanitize user-supplied input, allowing malicious script content to be saved within the application’s database. This malicious content is then delivered to other users when they access legitimate pages, such as product listings, customer records, administrative interfaces, or submission forms.

CVE-2026-48414 carries a CVSS score of 7.7 and necessitates authenticated administrator privileges, user interaction, and high attack complexity for exploitation. Conversely, CVE-2026-48413 is rated 8.7, indicating a higher level of accessibility. This particular XSS flaw requires an authenticated account with low privileges and user interaction but does not demand administrator access. The security update, tracked as APSB26-92, was released on August 11, 2026, with a priority rating of 2.

In a real-world scenario, threat actors could leverage a compromised customer, employee, or partner account to inject malicious scripts into the commerce platform, affecting subsequent users who view the compromised content.

Additional Authorization Bypass Vulnerabilities

Another critical flaw, CVE-2026-48415, specifically impacts Adobe Commerce B2B deployments. This incorrect authorization vulnerability could permit an authenticated attacker, even without administrative rights, to circumvent existing security features. Adobe assigned this a CVSS score of 7.6. Furthermore, CVE-2026-48416, also an authorization issue rated 7.5, presents a risk where an unauthenticated attacker could bypass security controls.

The update also addresses CVE-2026-48411, an important authorization flaw with a CVSS score of 6.8, and CVE-2026-48412, a moderate privilege escalation issue rated 2.7. While these latter vulnerabilities have lower severity scores, organizations are advised to implement the entire security package rather than selectively patching only the critical bugs.

Affected products include Adobe Commerce versions 2.4.4 through 2.4.9 that have the July 2026 security update or earlier, Magento Open Source versions 2.4.6 through 2.4.9, and several Adobe Commerce B2B releases. Adobe recommends updating to the August 2026 releases without delay.

Adobe has stated that it is currently unaware of any active exploitation of these vulnerabilities in the wild. However, the public disclosure of security advisories often increases interest from attackers, especially for internet-facing stores that remain unpatched.

What You Should Do

  • Immediately apply the relevant August 2026 security updates for Adobe Commerce and Magento Open Source.
  • Review all privileged user accounts for any suspicious activity or unauthorized changes.
  • Actively monitor application logs for unusual patterns or indicators of compromise.
  • Verify that web application firewall (WAF) rules and access control policies are properly configured and functioning effectively to mitigate potential exploitation attempts.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitPatchSecurityThreatVulnerability

Share Article

David kimber

David kimber

David is a penetration tester turned security journalist with expertise in mobile security, IoT vulnerabilities, and exploit development. As an OSCP-certified security professional, David brings hands-on technical experience to his reporting on vulnerabilities and security research. His articles often feature detailed technical analysis of exploits and provide actionable defense recommendations. David maintains an active presence in the security research community and has contributed to multiple open-source security tools.

Previous Post

Cisco ASA, FTD Critical 0-Day Lets Attackers Trigger DoS

Next Post

Trump Authorizes Private Firms for Cyber Operations Against Foreign Criminals

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
City-Forum Hackers Exploit Salesforce, ServiceNow Critical Vulnerabilities
August 12, 2026
Palo Alto Networks Patches 11 Vulnerabilities in PAN-OS, GlobalProtect, Prisma Access
August 12, 2026
China-linked Hackers Use AI Agents to Attack Taiwan Government Websites
August 12, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
Emy Elsamnoudy
Emy Elsamnoudy
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us