tlder@devAdobe's August fixes include an unauthenticated RCE in Commerce
tlder@dev:~$
Security/CVEs/Advisories

Adobe's August fixes include an unauthenticated RCE in Commerce

  • Shipped
  • Action required

Rounding out the patch day, Adobe pushed fixes for four critical bugs in Commerce and Experience Manager. CVE-2026-48358 is the ugly one — arbitrary code execution with no user interaction required. CVE-2026-48356 sits just behind it, a dangerous-file-upload path that reaches code execution after a click. Run a Commerce storefront? Don't sit on these.