Critical Adobe Commerce Flaws Let Attackers Execute Code (CVE-2024-20724, CVE-2024-20725)
Key Takeaways Adobe has released an urgent security update for critical vulnerabilities in Adobe Commerce and Magento Open Source. The most severe flaw, CVE-2026-71362, is an authorization bypass...
Key Takeaways
- Adobe has released an urgent security update for critical vulnerabilities in Adobe Commerce and Magento Open Source.
- The most severe flaw, CVE-2026-71362, is an authorization bypass allowing unauthenticated attackers to escalate privileges with a CVSS score of 9.1.
- Multiple other vulnerabilities, including critical stored cross-site scripting (XSS) and authorization bypasses, could lead to arbitrary code execution or security feature circumvention.
- Affected versions include Adobe Commerce 2.4.4 through 2.4.9 and Magento Open Source 2.4.6 through 2.4.9.
- Patches were released on August 11, 2026, and immediate application is strongly recommended.
Adobe has issued a critical security bulletin addressing several serious vulnerabilities within its Adobe Commerce and Magento Open Source platforms. These flaws, if exploited, could allow malicious actors to bypass security measures, achieve elevated privileges, and execute arbitrary code on affected systems.
Table Of Content
The most significant vulnerability identified is CVE-2026-71362, an authorization bypass with a CVSS score of 9.1, categorizing it as critical. This flaw enables an unauthenticated attacker to remotely escalate privileges without requiring administrative access. Adobe highlighted the severity of this issue, noting its potential to expose sensitive data and facilitate unauthorized modifications within compromised commerce environments.
Adobe Commerce Vulnerabilities Detailed
Critical Stored Cross-Site Scripting (XSS) Flaws
Among the patched issues are two critical stored cross-site scripting (XSS) vulnerabilities, CVE-2026-48414 and CVE-2026-48413. Successful exploitation of either of these could lead to arbitrary code execution.
Stored XSS vulnerabilities arise when an application fails to properly sanitize user-supplied input, allowing malicious script content to be saved within the application’s database. This malicious content is then delivered to other users when they access legitimate pages, such as product listings, customer records, administrative interfaces, or submission forms.
CVE-2026-48414 carries a CVSS score of 7.7 and necessitates authenticated administrator privileges, user interaction, and high attack complexity for exploitation. Conversely, CVE-2026-48413 is rated 8.7, indicating a higher level of accessibility. This particular XSS flaw requires an authenticated account with low privileges and user interaction but does not demand administrator access. The security update, tracked as APSB26-92, was released on August 11, 2026, with a priority rating of 2.
In a real-world scenario, threat actors could leverage a compromised customer, employee, or partner account to inject malicious scripts into the commerce platform, affecting subsequent users who view the compromised content.
Additional Authorization Bypass Vulnerabilities
Another critical flaw, CVE-2026-48415, specifically impacts Adobe Commerce B2B deployments. This incorrect authorization vulnerability could permit an authenticated attacker, even without administrative rights, to circumvent existing security features. Adobe assigned this a CVSS score of 7.6. Furthermore, CVE-2026-48416, also an authorization issue rated 7.5, presents a risk where an unauthenticated attacker could bypass security controls.
The update also addresses CVE-2026-48411, an important authorization flaw with a CVSS score of 6.8, and CVE-2026-48412, a moderate privilege escalation issue rated 2.7. While these latter vulnerabilities have lower severity scores, organizations are advised to implement the entire security package rather than selectively patching only the critical bugs.
Affected products include Adobe Commerce versions 2.4.4 through 2.4.9 that have the July 2026 security update or earlier, Magento Open Source versions 2.4.6 through 2.4.9, and several Adobe Commerce B2B releases. Adobe recommends updating to the August 2026 releases without delay.
Adobe has stated that it is currently unaware of any active exploitation of these vulnerabilities in the wild. However, the public disclosure of security advisories often increases interest from attackers, especially for internet-facing stores that remain unpatched.
What You Should Do
- Immediately apply the relevant August 2026 security updates for Adobe Commerce and Magento Open Source.
- Review all privileged user accounts for any suspicious activity or unauthorized changes.
- Actively monitor application logs for unusual patterns or indicators of compromise.
- Verify that web application firewall (WAF) rules and access control policies are properly configured and functioning effectively to mitigate potential exploitation attempts.
Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.



No Comment! Be the first one.