Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive information. Exploitation of this issue does not require user interaction.
CVSS Score
7.5
EPSS Score
0.005
Published
2026-09-08
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to restricted resources. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS Score
8.6
EPSS Score
0.004
Published
2026-09-08
Adobe Commerce is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to access unauthorized files or directories outside the intended restrictions, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS Score
7.6
EPSS Score
0.008
Published
2026-09-08
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. An attacker with high privileges could leverage this vulnerability to bypass security measures and gain unauthorized write access, causing a limited disruption to availability. Exploitation of this issue does not require user interaction. Scope is changed.
CVSS Score
8.7
EPSS Score
0.005
Published
2026-09-08
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
CVSS Score
9.3
EPSS Score
0.008
Published
2026-09-08
Adobe Commerce is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.
CVSS Score
9.3
EPSS Score
0.008
Published
2026-09-08
CVE-2026-85880
Known exploited
Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.
CVSS Score
7.8
EPSS Score
0.006
Published
2026-09-08
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.
CVSS Score
5.5
EPSS Score
0.004
Published
2026-09-08
Heap-based buffer overflow in Windows Print Spooler Components allows an unauthorized attacker to execute code over a network.
CVSS Score
8.8
EPSS Score
0.004
Published
2026-09-08
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
CVSS Score
7.0
EPSS Score
0.002
Published
2026-09-08


Contact Us

Shodan ® - All rights reserved