EN

critical CVE-2026-76200, CVE-2026-76201

Adobe Commerce: Cross-site scripting possible

NVD (NIST) reports one vulnerability in Adobe Commerce with severity critical. The stated impact is cross-site scripting. Affected: CVE-2026-76200, CVE-2026-76201. The full description, affected versions and recommended action are available from NVD (NIST).

CVSS
9.3

What this means for you

Attackers can run code in your users' browsers. This mainly affects publicly reachable portals and login forms, where sessions can be taken over.

Contact

Reputation takes years. Destruction takes seconds.

Talk to us before somebody else does. The first conversation is free and we reply the same business day.