External risk intelligence

Adobe Commerce Stored Cross-Site Scripting Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.3)

CVE-2026-76201

Adobe Commerce (Magento) is a web-based e-commerce platform designed to be publicly accessible. Stored XSS vulnerabilities in such applications are commonly reachable via the internet-facing storefront or administrative interfaces, as these platforms are intended for public browsing and interaction.

Cross-site Scripting

Adobe Commerce

before 2.4.42.4.42.4.52.4.6

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability impacts Adobe Commerce, a widely used e-commerce platform. It involves the potential for attackers to inject malicious scripts into the platform, which could then be executed in a user's browser, potentially leading to unauthorized access or control over accounts. The primary concern is to confirm if our organization utilizes this technology and if it is exposed externally.

  • Allows script injection, risking account control.
  • Important for e-commerce platforms handling transactions.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by submitting malicious scripts through exposed form fields on an Adobe Commerce site. When a user later views the page containing these injected scripts, the malicious JavaScript could execute in their browser. This could potentially allow the attacker to gain elevated access or control over the victim's account or session, as the vulnerability can alter the scope of its impact.

  • No authentication required.
  • Submit malicious scripts via form fields.
  • Execute scripts in victim's browser.

Live Threat

Current exploitation, exposure, and threat context

A stored cross-site scripting vulnerability in Adobe Commerce could allow an attacker to inject malicious scripts into form fields. When a victim browses a page with the vulnerable field, these scripts may execute in their browser, potentially leading to unauthorized access or control over their account or session.

  • User session data and account control.
  • Malicious scripts injected into form fields.
  • Elevated access or control over victim accounts.

Operational Fix

Recommended remediation, mitigation, and detection steps

This stored Cross-Site Scripting vulnerability in Adobe Commerce requires coordinated action between application owners, infrastructure teams, and security operations. The first step is to identify all instances of Adobe Commerce, determine their internet exposure and business criticality, and confirm ownership. Once these are established, a risk-based remediation plan can be developed, considering vendor coordination and maintenance windows.

  • Application owners and platform teams.
  • Confirm internet exposure and business criticality.
  • Plan remediation based on risk assessment.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Adobe Commerce?

Adobe Commerce, formerly known as Magento, is a comprehensive web-based platform used by businesses to build and manage online stores. It handles essential e-commerce functions like product catalogs, shopping carts, and customer checkout processes, making it a central hub for digital transactions.

What does CVE-2026-76201 mean by stored XSS?

This vulnerability falls under the CWE-79 weakness class, known as Cross-Site Scripting. It means the application fails to properly sanitize user input in form fields, allowing malicious code to be permanently saved on the server. When other users visit the affected page, their browser unknowingly runs this saved script.

How does an attacker trigger this vulnerability?

An attacker triggers this by submitting harmful JavaScript through specific, vulnerable input forms on the site. The bug does not require the attacker to have administrative privileges or existing authentication to submit the script. Simply navigating to a page that does not contain these specific vulnerable fields will not result in script execution.

Is my Adobe Commerce instance at risk?

Halo Surface Signal indicates that Adobe Commerce is generally designed for public access, making it highly likely that instances are exposed to the internet. If your platform has public-facing storefronts or administrative interfaces, the potential for an attacker to inject and store malicious scripts is significantly higher.

What should I do first to address this?

Begin by creating an inventory of all Adobe Commerce deployments within your environment. Verify which instances are accessible from the internet and identify the business owners responsible for each. Once you have a complete list, coordinate with your technical teams to prioritize these assets for vendor-provided updates.

References