CVE-2026-21360
published 2026-03-11CVE-2026-21360: Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a…
PriorityP338medium6.8CVSS 3.1
AVNACLPRHUINSCCHINAN
EPSS
0.64%
46.2th percentile
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restricted path. Exploitation of this issue does not require user interaction.
Affected
21 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | adobe_commerce | <= 2.4.4-p16 | — |
| adobe | commerce | < 2.4.4 | 2.4.4 |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce | — | — |
| adobe | commerce_b2b | < 1.3.3 | 1.3.3 |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | commerce_b2b | — | — |
| adobe | magento | < 2.4.5 | 2.4.5 |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
| adobe | magento | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Wiz
CVE-2026-21291 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.8
CVE-2026-21291 [MEDIUM] CVE-2026-21291 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21291 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Source : NVD
## 4.8
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 4.8
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.8
Exploitation Probability (EPSS) 0.1
Affected
Wiz
CVE-2026-21295 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 3.1
CVE-2026-21295 [LOW] CVE-2026-21295 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21295 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a URL Redirection to Untrusted Site ('Open Redirect') vulnerability. An attacker could leverage this vulnerability to redirect users to malicious websites. Exploitation of this issue requires user interaction.
Source : NVD
## 3.1
Score
Published March 11, 2026
Severity LOW
CNA Score 3.1
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.4
Exploitation Probability (EPSS) N/A
Affected packages and libraries
cpe:2.3:a:adobe:commerce
Sources
Linux Severity LOW
Wiz
CVE-2026-21359 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-21359 [MEDIUM] CVE-2026-21359 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21359 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and have limited impact to the integrity and availability of data. The exploit depends on conditions beyond the attacker's control. Exploitation of this issue does not require user interaction.
Source : NVD
## 4.7
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 4.7
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probabilit
Wiz
CVE-2026-21293 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21293 [MEDIUM] CVE-2026-21293 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21293 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and access unauthorized resources. Exploitation of this issue does not require user interaction.
Source : NVD
## 5.5
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.7
Exploitation Probability (EPSS) 0.1
Aff
Wiz
CVE-2026-21309 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-21309 [HIGH] CVE-2026-21309 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21309 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of data. Exploitation of this issue does not require user interaction.
Source : NVD
## 7.5
Score
Published March 11, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.7
Exploitation Probability (EPSS) 0.1
Affected packages and librar
Wiz
CVE-2026-21361 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-21361 [MEDIUM] CVE-2026-21361 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21361 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vvulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Source : NVD
## 8.1
Score
Published March 11, 2026
Severity HIGH
Wiz
CVE-2026-21290 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.7
CVE-2026-21290 [HIGH] CVE-2026-21290 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21290 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Source : NVD
## 8.7
Score
Published March 11, 2026
Severity HIGH
C
Wiz
CVE-2026-21285 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-21285 [MEDIUM] CVE-2026-21285 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21285 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.
Source : NVD
## 4.3
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15
Exploitation Probability (EPSS) N/A
Affect
Wiz
CVE-2026-21297 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-21297 [MEDIUM] CVE-2026-21297 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21297 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized access to a feature. Exploitation of this issue does not require user interaction.
Source : NVD
## 4.3
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 15
Exploitation Probability (EPSS) N/A
Affect
Wiz
CVE-2026-21294 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.5
CVE-2026-21294 [MEDIUM] CVE-2026-21294 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21294 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. A high-privileged attacker could exploit this vulnerability to manipulate server-side requests and bypass security controls. Exploitation of this issue does not require user interaction.
Source : NVD
## 5.5
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.5
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 17.7
Exploitation Probability (EPSS) 0.1
Affected
Wiz
CVE-2026-21284 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 8.1
CVE-2026-21284 [HIGH] CVE-2026-21284 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21284 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Source : NVD
## 8.1
Score
Published March 11, 2026
Severity HIGH
Wiz
CVE-2026-21289 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2026-21289 [HIGH] CVE-2026-21289 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21289 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized view access of data. Exploitation of this issue does not require user interaction.
Source : NVD
## 7.5
Score
Published March 11, 2026
Severity HIGH
CNA Score 7.5
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 32.7
Exploitation Probability (EPSS) 0.1
Affected packages and librar
Wiz
CVE-2026-21310 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-21310 [MEDIUM] CVE-2026-21310 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21310 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could result in a security feature bypass, with limited impact to integrity. Exploitation of this issue does not require user interaction.
Source : NVD
## 5.3
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 62.9
Exploitation Probability (EPSS) 0.4
Affected packages and libraries
cpe:2.3:a:adobe:commerce
Sources
Linux Severity MEDIUM No Fix Added at:
Wiz
CVE-2026-21286 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-21286 [MEDIUM] CVE-2026-21286 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21286 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized view access of data. Exploitation of this issue does not require user interaction.
Source : NVD
## 5.3
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 21.2
Exploitation Probability (EPSS) 0.1
Affected packages
Wiz
CVE-2026-21292 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.4
CVE-2026-21292 [MEDIUM] CVE-2026-21292 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21292 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker attacker to inject malicious scripts into vulnerable form fields. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Source : NVD
## 5.4
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.4
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 8.7
Exploitation Probability (EPSS) N/A
Af
Wiz
CVE-2026-21282 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-21282 [MEDIUM] CVE-2026-21282 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21282 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing limited impact to application availability. Exploitation of this issue does not require user interaction.
Source : NVD
## 5.3
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 5.3
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 49.4
Exploitation Probability (EPSS) 0.3
Affe
Wiz
CVE-2026-21296 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-21296 [MEDIUM] CVE-2026-21296 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21296 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage this vulnerability to bypass security measures and gain limited unauthorized view access of data. Exploitation of this issue does not require user interaction.
Source : NVD
## 4.3
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 4.3
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 13.2
Exploitation Probability (EPSS) N/A
Affe
Wiz
CVE-2026-21360 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-21360 [MEDIUM] CVE-2026-21360 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21360 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a security feature bypass. A high-privileged attacker could leverage this vulnerability to access unauthorized files or directories outside the intended restricted path. Exploitation of this issue does not require user interaction.
Source : NVD
## 6.8
Score
Published March 11, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
Adobe Commerce
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percen
Wiz
CVE-2026-21311 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 5.3
CVE-2026-21311 [MEDIUM] CVE-2026-21311 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-21311 :
Adobe Commerce vulnerability analysis and mitigation
Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim’s browser when they browse to the page containing the vulnerable field. A successful attacker can abuse this to achieve session takeover, increasing the confidentiality, and integrity impact to high. Exploitation of this issue requires user interaction in that a victim must browse to the page containing the vulnerable field.
Source : NVD
## 8
Score
Published March 11, 2026
Severity HIGH
CN
2026-03-11
Published