Latest Security Updates

View All →
Security Research

CVE-2026-48359 (CRITICAL) CVSS 9.6

🔴 Severity: CRITICAL (CVSS 9.6)

Adobe Experience Manager is affected by an Improper Restriction of XML External Entity Reference (‘XXE’) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could exploit this …

Security Research

CVE-2026-48358 (CRITICAL) CVSS 9.1

🔴 Severity: CRITICAL (CVSS 9.1)

Adobe Commerce is affected by an Improper Encoding or Escaping of Output vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed.

Published: …

Security Research

CVE-2026-48356 (CRITICAL) CVSS 9.6

🔴 Severity: CRITICAL (CVSS 9.6)

Adobe Commerce is affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, …

Security Research

CVE-2026-48259 (CRITICAL) CVSS 9.6

🔴 Severity: CRITICAL (CVSS 9.6)

Adobe Experience Manager is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in arbitrary code execution in the context of the current user. A low-privileged attacker could leverage this vulnerability to issue unauthorized server-side …

Security Research

CVE-2026-47992 (HIGH) CVSS 7.2

🟠 Severity: HIGH (CVSS 7.2)

Adobe Commerce is affected by an Improper Neutralization of Special Elements used in an SQL Command (‘SQL Injection’) vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could exploit this …