• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Vital Adobe Commerce Flaw Lets Unauthenticated Attackers Escalate Privileges

Admin by Admin
August 13, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


Adobe has launched safety updates for Adobe Commerce, Adobe Commerce B2B, and Magento Open Supply to handle a number of crucial vulnerabilities.

One of the vital critical points is a high-impact privilege-escalation flaw, tracked as CVE-2026-71362, which could be exploited with out authentication.

This vulnerability arises from incorrect authorization controls and has a CVSS base rating of 9.1 out of 10. Adobe warns that profitable exploitation may enable attackers to bypass safety measures, execute arbitrary code, or elevate privileges inside susceptible e-commerce environments.

Vital Adobe Commerce Flaw

Essentially the most extreme flaw impacts Adobe Commerce installations working the July 2026 security-update builds and earlier, particularly variations 2.4.4 by means of 2.4.9.

The vulnerability has the CVSS vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N, indicating that it’s remotely exploitable, requires no attacker privileges or person interplay, and might considerably influence on confidentiality and integrity.

Whereas availability will not be straight affected, an attacker with elevated permissions may entry delicate retailer information, modify utility settings, or set up a foothold for additional compromise.

Adobe’s bulletin APSB26-92, launched on August 11, 2026, additionally addresses a number of different crucial points, together with authorization flaws and saved cross-site scripting (XSS) vulnerabilities.

One notable unauthenticated incorrect-authorization vulnerability, CVE-2026-48416, is rated 7.5 and might trigger a security-feature bypass.

Though it’s not as extreme as CVE-2026-71362, its lack of authentication necessities makes it significantly regarding for internet-facing storefronts and administrative interfaces. Safety researcher Wohlie reported this flaw.

Two saved XSS vulnerabilities, CVE-2026-48413 and CVE-2026-48414, can result in arbitrary code execution underneath sure circumstances. CVE-2026-48413 has a CVSS rating of 8.7 and requires low-privilege authentication and person interplay.

On the identical time, CVE-2026-48414 is rated 7.7 and moreover requires administrative privileges. Adobe has additionally patched CVE-2026-48415, a crucial security-feature bypass challenge affecting the Adobe Commerce B2B part, together with two lower-severity authorization flaws, CVE-2026-48411 and CVE-2026-48412.

Organizations are urged to improve instantly to the August 2026 builds. Adobe Commerce customers ought to replace to one of many following variations: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, or 2.4.4-2026-aug, relying on their supported launch department.

Adobe Commerce B2B customers ought to apply the corresponding packages from 1.3.3 to 1.5.3 for August 2026, whereas Magento Open Supply customers ought to replace their supported deployments from 2.4.6 to 2.4.9.

Adobe has assigned the replace a Precedence 2 score and said that it’s not conscious of any exploitation of the vulnerabilities addressed by APSB26-92 within the wild.

Nevertheless, as a result of unauthenticated nature and low assault complexity of CVE-2026-71362, immediate patching is essential. Directors also needs to evaluate privileged account exercise, examine sudden configuration modifications, validate extension integrity, and make sure that acceptable internet utility firewalls and entry management insurance policies shield uncovered Commerce cases.

Cease new phishing & malware earlier than they compromise your online business. Combine reside intel from 15K SOCs all over the world

Tags: AdobeAttackersCommerceCriticalEscalateFlawLetsprivilegesUnauthenticated
Admin

Admin

Next Post
5 Greatest Android Tablets in 2026: Samsung, TCL, Amazon, and Extra

5 Greatest Android Tablets in 2026: Samsung, TCL, Amazon, and Extra

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

The right way to use Netdiscover to map and troubleshoot networks

The right way to use Netdiscover to map and troubleshoot networks

August 26, 2025
Learn how to Develop an App Like Uber in 2026

Learn how to Develop an App Like Uber in 2026

May 8, 2026
Prime AI Legacy System Modernization Firms in 2026

Prime AI Legacy System Modernization Firms in 2026

July 10, 2026
Accessibility With out Compromise – Chefio

Accessibility With out Compromise – Chefio

February 3, 2026
Information to Grocery Supply App Growth for Your Enterprise

Information to Grocery Supply App Growth for Your Enterprise

February 11, 2026

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Henry Cavill’s 2-Hour Motion-Film Masterpiece With a Secret 007 Connection Is Formally Free to Stream

Henry Cavill’s 2-Hour Motion-Film Masterpiece With a Secret 007 Connection Is Formally Free to Stream

August 13, 2026
Advancing medical AI for video consultations

Advancing medical AI for video consultations

August 13, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved