NPM · SEPTEMBER 2026 · EARLY WARNING

Adobe Commerce Stored XSS Vulnerability: Early Warning

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.3
Affected component
adobe commerce (npm)
Affected versions
>= 2.4.4-NA, <= 2.4.4-NA or >= 2.4.4-p1, <= 2.4.4-p1 or >= 2.4.4-p10, <= 2.4.4-p10 or >= 2.4.4-p11, <= 2.4.4-p11 or >= 2.4.4-p12, <= 2.4.4-p12 or >= 2.4.4-p13, <= 2.4.4-p13 or >= 2.4.4-p2, <= 2.4.4-p2 or >= 2.4.4-p3, <= 2.4.4-p3 or >= 2.4.4-p4, <= 2.4.4-p4 or >= 2.4.4-p5, <= 2.4.4-p5 or >= 2.4.4-p6, <= 2.4.4-p6 or >= 2.4.4-p7, <= 2.4.4-p7 or >= 2.4.4-p8, <= 2.4.4-p8 or >= 2.4.4-p9, <= 2.4.4-p9 or >= 2.4.5-NA, <= 2.4.5-NA or >= 2.4.5-p1, <= 2.4.5-p1 or >= 2.4.5-p10, <= 2.4.5-p10 or >= 2.4.5-p11, <= 2.4.5-p11 or >= 2.4.5-p12, <= 2.4.5-p12 or >= 2.4.5-p13, <= 2.4.5-p13 or >= 2.4.5-p14, <= 2.4.5-p14 or >= 2.4.5-p2, <= 2.4.5-p2 or >= 2.4.5-p3, <= 2.4.5-p3 or >= 2.4.5-p4, <= 2.4.5-p4 or >= 2.4.5-p5, <= 2.4.5-p5 or >= 2.4.5-p6, <= 2.4.5-p6 or >= 2.4.5-p7, <= 2.4.5-p7 or >= 2.4.5-p8, <= 2.4.5-p8 or >= 2.4.5-p9, <= 2.4.5-p9 or >= 2.4.6-NA, <= 2.4.6-NA or >= 2.4.6-p1, <= 2.4.6-p1 or >= 2.4.6-p10, <= 2.4.6-p10 or >= 2.4.6-p11, <= 2.4.6-p11 or >= 2.4.6-p12, <= 2.4.6-p12 or >= 2.4.6-p13, <= 2.4.6-p13 or >= 2.4.6-p2, <= 2.4.6-p2 or >= 2.4.6-p3, <= 2.4.6-p3 or >= 2.4.6-p4, <= 2.4.6-p4 or >= 2.4.6-p5, <= 2.4.6-p5 or >= 2.4.6-p6, <= 2.4.6-p6 or >= 2.4.6-p7, <= 2.4.6-p7 or >= 2.4.6-p8, <= 2.4.6-p8 or >= 2.4.6-p9, <= 2.4.6-p9 or >= 2.4.7-NA, <= 2.4.7-NA or >= 2.4.7-b1, <= 2.4.7-b1 or >= 2.4.7-b2, <= 2.4.7-b2 or >= 2.4.7-beta3, <= 2.4.7-beta3 or >= 2.4.7-p3, <= 2.4.7-p3 or >= 2.4.7-p4, <= 2.4.7-p4 or >= 2.4.7-p5, <= 2.4.7-p5 or >= 2.4.7-p6, <= 2.4.7-p6 or >= 2.4.7-p7, <= 2.4.7-p7 or >= 2.4.7-p8, <= 2.4.7-p8 or >= 2.4.8-NA, <= 2.4.8-NA or >= 2.4.8-beta1, <= 2.4.8-beta1 or >= 2.4.8-beta2, <= 2.4.8-beta2 or >= 2.4.8-p1, <= 2.4.8-p1 or >= 2.4.8-p2, <= 2.4.8-p2 or >= 2.4.8-p3, <= 2.4.8-p3 or >= 2.2.0-RC1.3, <= 2.2.0-RC1.3 or >= 2.2.0-RC1.2, <= 2.2.0-RC1.2 or >= 2.2.0-RC1.1, <= 2.2.0-RC1.1 or >= 2.1.0, <= 2.1.0 or >= 2.1.0-rc3, <= 2.1.0-rc3 or >= 2.1.0-rc2, <= 2.1.0-rc2 or >= 2.1.0-rc1, <= 2.1.0-rc1 or >= 2.0.0, <= 2.0.0 or >= 2.0.0-rc, <= 2.0.0-rc or >= 0.74.0-beta1, <= 0.74.0-beta1 or >= 0.42.0-beta3, <= 0.42.0-beta3 or >= 0.1.0-alpha108, <= 0.1.0-alpha108 or >= 0.42.0-beta1, <= 0.42.0-beta1 or >= 0.1.0-alpha107, <= 0.1.0-alpha107 or >= 0.1.0-alpha106, <= 0.1.0-alpha106 or >= 0.1.0-alpha105, <= 0.1.0-alpha105 or >= 0.1.0-alpha104, <= 0.1.0-alpha104 or >= 0.1.0-alpha103, <= 0.1.0-alpha103 or >= 0.1.0-alpha102, <= 0.1.0-alpha102 or >= 0.1.0-alpha101, <= 0.1.0-alpha101 or >= 0.1.0-alpha100, <= 0.1.0-alpha100 or >= 0.1.0-alpha99, <= 0.1.0-alpha99 or >= 0.1.0-alpha98, <= 0.1.0-alpha98 or >= 0.1.0-alpha97, <= 0.1.0-alpha97 or >= 0.1.0-alpha96, <= 0.1.0-alpha96 or >= 0.1.0-alpha95, <= 0.1.0-alpha95 or >= 0.1.0-alpha94, <= 0.1.0-alpha94 or >= 0.1.0-alpha93, <= 0.1.0-alpha93 or >= 0.1.0-alpha92, <= 0.1.0-alpha92 or >= 0.1.0-alpha91, <= 0.1.0-alpha91 or >= 0.1.0-alpha90, <= 0.1.0-alpha90 or >= 0.1.0-alpha89, <= 0.1.0-alpha89
Patched version
Not yet available
CVE-2026-76200

An early warning has been issued for a critical stored Cross-Site Scripting (XSS) vulnerability in Adobe Commerce. This vulnerability could allow an attacker to inject malicious scripts into form fields, potentially compromising user accounts or sessions.

What happened

Adobe Commerce is reportedly affected by a stored Cross-Site Scripting (XSS) vulnerability. This vulnerability could be exploited by an attacker to inject malicious scripts into vulnerable form fields. When a victim browses to a page containing the vulnerable field, the malicious JavaScript may be executed in their browser, potentially leading to elevated access or control over the victim's account or session.

The vulnerability affects a wide range of Adobe Commerce versions, from 0.1.0-alpha89 to 2.4.8-p3. Users of these versions should take immediate action to assess their exposure and apply necessary mitigations.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If adobe commerce is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Adobe Commerce version 0.1.0-alpha89 or later, you may be affected by this vulnerability. Check the version range provided in the threat data to confirm.

What should I do right now?

Immediately upgrade to the latest version of Adobe Commerce and review your custom form fields for potential injection points.

Is there an official fix available?

No official fix has been published yet. Monitor the primary sources for updates on this vulnerability.

Sources

Join the 0Day waitlist →

← Back to all threats