Adobe Commerce Vulnerabilities
CVE security advisories and vulnerability history for Adobe Commerce by Adobe.
Last updated
CVE security advisories and vulnerability history for Adobe Commerce by Adobe.
Last updated
Adobe Commerce has 222 published CVE records since 2021, of which 3 are in CISA's Known Exploited Vulnerabilities catalog and 3 have a known public exploit. The average CVSS base score across scored CVEs is 6.6.
This page aggregates every publicly disclosed vulnerability (CVE) affecting Adobe Commerce, with a severity breakdown, the affected and patched versions, the most common weakness types, and the full CVE list.
How the CVSS severity of Adobe Commerce's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
3
3 of Adobe Commerce's CVEs are confirmed exploited in the wild.
Public exploits
3
3 of Adobe Commerce's CVEs have a known public exploit available.
Browse every Adobe Commerce version named in a CVE, then pick one to see only the CVEs that affect it.
222 CVEs
Added to CISA KEV 2026-09-08
Showing 30 of 222
The CWE weakness categories most often found in Adobe Commerce CVEs. Follow any weakness for its full explanation.
How many Adobe Commerce CVEs were published each year.
Browse vulnerabilities for other products by Adobe.
Common questions about Adobe Commerce vulnerabilities.
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Monitor new Adobe Commerce vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.