CVE-2026-48358
Adobe Commerce 2.4.4 is vulnerable to improper encoding or escaping of output, allowing an attacker with high privileges to run arbitrary code on the server without user interaction.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Adobe Commerce version 2.4.4, used by e‑commerce site operators.
Real-world impact
An attacker who can gain high‑privilege access can execute any code on the server, potentially taking full control, stealing data, or disrupting services.
Why this severity
The CVSS score of 9.1 reflects that the vulnerability requires high privileges, has no user interaction, and grants full confidentiality, integrity, and availability impact with scope change.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources
Timeline
- Jul 14, 2026 · 19d agoPublishedDisclosed and added to the National Vulnerability Database.
- Jul 29, 2026 · 4d agoAdvisory updatedThe NVD record was last revised.
How it’s attacked
References & advisories
- helpx.adobe.com/security/products/magento/a…vendor advisory