Junglewise Threat Intelligence

CVE-2026-34652: Adobe Commerce denial of service via vulnerable dependency

CVE-2026-34652 · Severity: high · CVSS 7.5 · Published 2026-05-12

Technologies: Adobe Commerce. Vendors: Adobe.

Executive brief

Adobe Commerce, a popular e-commerce platform used for online storefronts, is affected by a security flaw in one of its third-party components. An attacker can exploit this to crash the website, making it unavailable to customers and disrupting business operations. This attack can be carried out remotely without any user interaction or login credentials.

Technical details

Adobe Commerce is vulnerable to a denial-of-service (DoS) condition due to the use of a vulnerable third-party dependency. The vulnerability allows a remote, unauthenticated attacker to trigger an application crash without requiring any user interaction. The attack vector is network-based with low complexity, targeting the availability of the service (Impact: High). While the specific third-party component is not named in the advisory, the issue is addressed in Adobe security bulletin APSB26-49. Users are advised to update to the latest patched versions of Adobe Commerce or Magento Open Source.

Affected products

  • Adobe Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier

Timeline

  • 2026-05-12: disclosed
  • 2026-05-12: advisory

References

Related threats