<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cpe:2.3:a:adobe:campaign:*:*:*:*:classic:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aadobecampaignclassic/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 03 Aug 2026 23:42:20 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aadobecampaignclassic/feed.xml" rel="self" type="application/rss+xml"/><item><title>Adobe Security Updates — August 2026</title><link>https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/</link><pubDate>Mon, 03 Aug 2026 23:42:20 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-adobe-security-updates/</guid><description>Roundup of Adobe security advisories published in August 2026.</description><content:encoded><![CDATA[<p>This roundup covers 24 Adobe security vulnerabilities. CVSS base scores range from 7.1 to 10.0. None are reported as actively exploited at the time of release. The issues affect Adobe Campaign Classic, Adobe Commerce, ColdFusion, ColdFusion 2025, Content Credentials Rust SDK, Lightroom Classic.</p>
<h2 id="summary">Summary</h2>
<table>
	<thead>
			<tr>
					<th>CVE</th>
					<th>Product</th>
					<th>Severity</th>
					<th>CVSS</th>
					<th>EPSS</th>
					<th>KEV</th>
					<th>Source</th>
			</tr>
	</thead>
	<tbody>
			<tr>
					<td><a href="#cve-2026-48362">CVE-2026-48362</a></td>
					<td>ColdFusion 2025 (&lt;= 2025.0.11)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48362">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71384">CVE-2026-71384</a></td>
					<td>n/a</td>
					<td>Critical</td>
					<td>9.6</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71384">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-21273">CVE-2026-21273</a></td>
					<td>ColdFusion 2025 (&lt;= 2025.0.11)</td>
					<td>High</td>
					<td>8.7</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21273">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-21279">CVE-2026-21279</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>8.2</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21279">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-25652">CVE-2026-25652</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25652">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-34635">CVE-2026-34635</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>8.4</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34635">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48385">CVE-2026-48385</a></td>
					<td>ColdFusion (&lt;= 2025.0.11)</td>
					<td>High</td>
					<td>7.7</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48385">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48386">CVE-2026-48386</a></td>
					<td>ColdFusion 2025 (&lt;= 2025.0.11)</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48386">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48439">CVE-2026-48439</a></td>
					<td>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</td>
					<td>High</td>
					<td>7.5</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48439">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48440">CVE-2026-48440</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48440">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48442">CVE-2026-48442</a></td>
					<td>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</td>
					<td>High</td>
					<td>7.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48442">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-27302">CVE-2026-27302</a></td>
					<td>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27302">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71362">CVE-2026-71362</a></td>
					<td>n/a</td>
					<td>Critical</td>
					<td>9.1</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71362">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-71398">CVE-2026-71398</a></td>
					<td>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</td>
					<td>Critical</td>
					<td>10.0</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71398">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-47940">CVE-2026-47940</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47940">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48397">CVE-2026-48397</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48397">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48405">CVE-2026-48405</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48405">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48406">CVE-2026-48406</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48406">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48407">CVE-2026-48407</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48407">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48408">CVE-2026-48408</a></td>
					<td>Lightroom Classic (&lt;= 15.4)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48408">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48410">CVE-2026-48410</a></td>
					<td>n/a</td>
					<td>High</td>
					<td>7.8</td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48410">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48413">CVE-2026-48413</a></td>
					<td>Adobe Commerce (&lt;= 2026-07-31)</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48413">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48415">CVE-2026-48415</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48415">NVD</a> (authoritative)</td>
			</tr>
			<tr>
					<td><a href="#cve-2026-48416">CVE-2026-48416</a></td>
					<td>n/a</td>
					<td></td>
					<td></td>
					<td></td>
					<td>no</td>
					<td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48416">NVD</a> (authoritative)</td>
			</tr>
	</tbody>
</table>
<h2 id="cve-2026-48362">CVE-2026-48362</h2>
<p>CVE-2026-48362 is a critical OS command injection vulnerability in Adobe ColdFusion 2023 and 2025 that allows unauthenticated, remote attackers to achieve arbitrary code execution. The vulnerability does not require user interaction and impacts the scope of the application, posing a significant risk to affected environments.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion 2025 (&lt;= 2025.0.11)</li>
<li>ColdFusion 2023 (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48362">https://nvd.nist.gov/vuln/detail/CVE-2026-48362</a></p>
<p>Related in this roundup: <a href="#cve-2026-21273">CVE-2026-21273</a>, <a href="#cve-2026-48386">CVE-2026-48386</a>.</p>
<h2 id="cve-2026-71384">CVE-2026-71384</h2>
<p>CVE-2026-71384 is an incorrect authorization vulnerability in Adobe ColdFusion 2023 and 2025. The flaw allows an unauthenticated, adjacent attacker to bypass security features, resulting in unauthorized read and write access, and potentially a denial-of-service condition. Although the vulnerable component is restricted to an administrative network zone by default, successful exploitation does not require user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71384">https://nvd.nist.gov/vuln/detail/CVE-2026-71384</a></p>
<h2 id="cve-2026-21273">CVE-2026-21273</h2>
<p>CVE-2026-21273 describes an improper input validation vulnerability in Adobe ColdFusion 2025 and 2023. A low-privileged attacker can exploit this flaw by enticing a user to open a malicious file, leading to unauthorized read and write access and privilege escalation on the affected system.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion 2025 (&lt;= 2025.0.11)</li>
<li>ColdFusion 2023 (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21273">https://nvd.nist.gov/vuln/detail/CVE-2026-21273</a></p>
<p>Related in this roundup: <a href="#cve-2026-48362">CVE-2026-48362</a>, <a href="#cve-2026-48386">CVE-2026-48386</a>.</p>
<h2 id="cve-2026-21279">CVE-2026-21279</h2>
<p>Adobe ColdFusion versions 2025 (&lt;= 2025.0.11) and 2023 (&lt;= 2023.0.22) are vulnerable to an improper input validation flaw that allows for a security feature bypass. An unauthenticated remote attacker can exploit this vulnerability to gain unauthorized read and limited write access to the affected system without requiring user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-21279">https://nvd.nist.gov/vuln/detail/CVE-2026-21279</a></p>
<h2 id="cve-2026-25652">CVE-2026-25652</h2>
<p>CVE-2026-25652 is an Incorrect Authorization vulnerability in Adobe ColdFusion 2025 and 2023 versions. A low-privileged attacker can exploit this flaw to escalate privileges and gain unauthorized read and write access to the system. Exploitation is local and does not require user interaction.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-25652">https://nvd.nist.gov/vuln/detail/CVE-2026-25652</a></p>
<h2 id="cve-2026-34635">CVE-2026-34635</h2>
<p>Adobe ColdFusion versions 2025 (&lt;= 2025.0.11) and 2023 (&lt;= 2023.0.22) contain a Use of Hard-coded Cryptographic Key vulnerability. A low-privileged attacker can exploit this issue to bypass security features and obtain unauthorized read and write access without user interaction. The vulnerability results in a scope change, potentially allowing for cross-security-domain impact.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-34635">https://nvd.nist.gov/vuln/detail/CVE-2026-34635</a></p>
<h2 id="cve-2026-48385">CVE-2026-48385</h2>
<p>Adobe ColdFusion is vulnerable to an OS command injection flaw (CVE-2026-48385) that allows low-privileged, remote attackers to bypass security features and gain unauthorized write access to the system. The vulnerability does not require user interaction and impacts the system scope.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion (&lt;= 2025.0.11)</li>
<li>ColdFusion (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48385">https://nvd.nist.gov/vuln/detail/CVE-2026-48385</a></p>
<h2 id="cve-2026-48386">CVE-2026-48386</h2>
<p>Adobe ColdFusion is vulnerable to a broken or risky cryptographic algorithm (CWE-327), which can be exploited by a remote, unauthenticated attacker to disclose sensitive memory contents. Successful exploitation allows for the unauthorized access to sensitive information without requiring user interaction.</p>
<p>Affected products:</p>
<ul>
<li>ColdFusion 2025 (&lt;= 2025.0.11)</li>
<li>ColdFusion 2023 (&lt;= 2023.0.22)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48386">https://nvd.nist.gov/vuln/detail/CVE-2026-48386</a></p>
<p>Related in this roundup: <a href="#cve-2026-48362">CVE-2026-48362</a>, <a href="#cve-2026-21273">CVE-2026-21273</a>.</p>
<h2 id="cve-2026-48439">CVE-2026-48439</h2>
<p>The CAI Content Credentials SDKs and command-line tool are vulnerable to an uncontrolled resource consumption issue (CWE-400). A remote, unauthenticated attacker can exploit this vulnerability to exhaust system resources, leading to a denial-of-service (DoS) condition. No user interaction is required for successful exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</li>
<li>Content Credentials Command-Line Tool (&lt;= c2patool-v0.27.5)</li>
<li>Content Credentials JS SDK (&lt;= @contentauth/c2pa@0.14.2)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48439">https://nvd.nist.gov/vuln/detail/CVE-2026-48439</a></p>
<p>Related in this roundup: <a href="#cve-2026-48442">CVE-2026-48442</a>.</p>
<h2 id="cve-2026-48440">CVE-2026-48440</h2>
<p>Adobe ColdFusion versions 2025 (&lt;= 2025.0.11) and 2023 (&lt;= 2023.0.22) are vulnerable to a heap-based buffer overflow. This vulnerability allows an unauthenticated, remote attacker to execute arbitrary code in the context of the current user without requiring user interaction. The exploitation process is non-deterministic, relying on specific environmental conditions.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48440">https://nvd.nist.gov/vuln/detail/CVE-2026-48440</a></p>
<h2 id="cve-2026-48442">CVE-2026-48442</h2>
<p>The Adobe Content Credentials SDK and associated tooling are vulnerable to a path traversal vulnerability (CWE-22) which allows an attacker to perform arbitrary file system reads. The vulnerability does not require user interaction and impacts multiple language-specific SDKs and the CLI tool.</p>
<p>Affected products:</p>
<ul>
<li>Content Credentials Rust SDK (&lt;= c2pa-v0.90.5)</li>
<li>Content Credentials Command-Line Tool (&lt;= c2patool-v0.27.5)</li>
<li>Content Credentials JS SDK (&lt;= @contentauth/c2pa-v0.27.5)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48442">https://nvd.nist.gov/vuln/detail/CVE-2026-48442</a></p>
<p>Related in this roundup: <a href="#cve-2026-48439">CVE-2026-48439</a>.</p>
<h2 id="cve-2026-27302">CVE-2026-27302</h2>
<p>Adobe Campaign Classic is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS v3.1 base score of 10.0 and does not require user interaction to exploit.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-27302">https://nvd.nist.gov/vuln/detail/CVE-2026-27302</a></p>
<p>Related in this roundup: <a href="#cve-2026-71398">CVE-2026-71398</a>.</p>
<h2 id="cve-2026-71362">CVE-2026-71362</h2>
<p>Adobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows an unauthenticated, remote attacker to perform privilege escalation. The vulnerability does not require user interaction and can be exploited to gain unauthorized access to sensitive resources.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71362">https://nvd.nist.gov/vuln/detail/CVE-2026-71362</a></p>
<h2 id="cve-2026-71398">CVE-2026-71398</h2>
<p>Adobe Campaign Classic (ACC) is vulnerable to an incorrect authorization flaw (CWE-863) that allows an unauthenticated remote attacker to execute arbitrary code. The vulnerability has a CVSS base score of 10.0 and does not require user interaction for exploitation.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Campaign Classic (&lt;= 7.4.3 build 9399)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-71398">https://nvd.nist.gov/vuln/detail/CVE-2026-71398</a></p>
<p>Related in this roundup: <a href="#cve-2026-27302">CVE-2026-27302</a>.</p>
<h2 id="cve-2026-47940">CVE-2026-47940</h2>
<p>Adobe Lightroom Classic is vulnerable to an integer overflow or wraparound condition that can lead to arbitrary code execution. The vulnerability is triggered when a user is enticed to open a maliciously crafted file, allowing an attacker to execute code within the context of the current user session.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-47940">https://nvd.nist.gov/vuln/detail/CVE-2026-47940</a></p>
<h2 id="cve-2026-48397">CVE-2026-48397</h2>
<p>Adobe Lightroom Classic is vulnerable to a deserialization of untrusted data issue that allows an attacker to achieve arbitrary code execution. The vulnerability requires user interaction, specifically the opening of a malicious file by the victim, which triggers the flaw within the application context.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48397">https://nvd.nist.gov/vuln/detail/CVE-2026-48397</a></p>
<h2 id="cve-2026-48405">CVE-2026-48405</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) flaw that allows an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption within the application context.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48405">https://nvd.nist.gov/vuln/detail/CVE-2026-48405</a></p>
<h2 id="cve-2026-48406">CVE-2026-48406</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. A local attacker can exploit this by convincing a user to open a specially crafted malicious file within the application.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48406">https://nvd.nist.gov/vuln/detail/CVE-2026-48406</a></p>
<h2 id="cve-2026-48407">CVE-2026-48407</h2>
<p>Adobe Lightroom Classic is susceptible to an out-of-bounds write vulnerability that can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the memory corruption issue within the application's process context.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48407">https://nvd.nist.gov/vuln/detail/CVE-2026-48407</a></p>
<h2 id="cve-2026-48408">CVE-2026-48408</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write (CWE-787) that allows for arbitrary code execution. Successful exploitation requires a user to open a specially crafted malicious file, which triggers the vulnerability in the context of the logged-in user.</p>
<p>Affected products:</p>
<ul>
<li>Lightroom Classic (&lt;= 15.4)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48408">https://nvd.nist.gov/vuln/detail/CVE-2026-48408</a></p>
<h2 id="cve-2026-48410">CVE-2026-48410</h2>
<p>Adobe Lightroom Classic is vulnerable to an out-of-bounds write, which can be exploited by an attacker to achieve arbitrary code execution. Successful exploitation requires the user to open a malicious file, making it a client-side execution risk.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48410">https://nvd.nist.gov/vuln/detail/CVE-2026-48410</a></p>
<h2 id="cve-2026-48413">CVE-2026-48413</h2>
<p>Adobe Commerce and Magento Open Source are vulnerable to a stored Cross-Site Scripting (XSS) attack via malicious input in form fields. A low-privileged attacker can inject scripts that execute in a victim's browser, potentially leading to unauthorized account or session control. This vulnerability involves a change in security scope.</p>
<p>Affected products:</p>
<ul>
<li>Adobe Commerce (&lt;= 2026-07-31)</li>
<li>Adobe Commerce B2B (&lt;= 2026-07-31)</li>
<li>Magento Open Source (&lt;= 2026-07-31)</li>
</ul>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48413">https://nvd.nist.gov/vuln/detail/CVE-2026-48413</a></p>
<h2 id="cve-2026-48415">CVE-2026-48415</h2>
<p>Adobe Commerce and Magento Open Source are vulnerable to an Incorrect Authorization flaw (CWE-863) that allows a low-privileged, remote attacker to bypass security controls. Successful exploitation grants unauthorized read and write access without requiring user interaction, potentially impacting data integrity and availability.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48415">https://nvd.nist.gov/vuln/detail/CVE-2026-48415</a></p>
<h2 id="cve-2026-48416">CVE-2026-48416</h2>
<p>CVE-2026-48416 is an incorrect authorization vulnerability in Adobe Commerce and Magento Open Source that allows remote, unauthenticated attackers to bypass security measures and gain unauthorized read access to sensitive data. The vulnerability does not require user interaction and is exploitable over the network.</p>
<p>Source: <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-48416">https://nvd.nist.gov/vuln/detail/CVE-2026-48416</a></p>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>roundup</category></item></channel></rss>