critical CVE-2026-76200, CVE-2026-76201
Adobe Commerce: Cross-site scripting possible
NVD (NIST) reports one vulnerability in Adobe Commerce with severity critical. The stated impact is cross-site scripting. Affected: CVE-2026-76200, CVE-2026-76201. The full description, affected versions and recommended action are available from NVD (NIST).
- CVSS
- 9.3
What this means for you
Attackers can run code in your users' browsers. This mainly affects publicly reachable portals and login forms, where sessions can be taken over.
All 4 advisories for Adobe Commerce
Original source
Insights
More articles
Weekly situation, week 36: 55 advisories, 12 critical
Between 30 Aug and 6 Sep 2026 our sources recorded 55 advisories: 12 critical, 43 high.
Weekly situation, week 35: 75 advisories, 21 critical
Between 23 Aug and 30 Aug 2026 our sources recorded 75 advisories: 21 critical, 54 high.
Weekly situation, week 34: 91 advisories, 9 critical
Between 16 Aug and 23 Aug 2026 our sources recorded 91 advisories: 9 critical, 82 high.
Contact
Reputation takes years. Destruction takes seconds.
Talk to us before somebody else does. The first conversation is free and we reply the same business day.