As cited
Copy frozen at (site build).
vulnerabilities
NCSC-2026-0344 [1.00] [H/H] Kwetsbaarheid verholpen in Adobe Commerce en Magento
Adobe has patched a vulnerability in the template engine of Adobe Commerce and Magento where special elements are not properly sanitized. An attacker can exploit this to execute arbitrary code remotely without user interaction by manipulating scope to escalate privileges or modify the execution context. Adobe reports the vulnerability is under active exploitation.
Why it matters: Organizations running Adobe Commerce or Magento instances are at immediate risk of remote code execution; patching should be prioritized given active exploitation in the wild.
- Source published
- First seen by Cybersecurity Tracker