Open Redirect Vulnerability in Adobe Commerce Products
CVE-2026-21295

3.1LOW

Key Information:

Vendor

Adobe

Vendor
CVE Published:
11 March 2026

What is CVE-2026-21295?

Adobe Commerce is affected by a security flaw that allows attackers to redirect users to harmful external sites. This vulnerability, identified as an 'Open Redirect,' can be exploited when users unintentionally click on malicious links. It’s crucial for users to ensure they are on trusted websites to avoid falling victim to this risk, which requires user interaction for exploitation. Updating to the latest versions and monitoring your security settings is strongly recommended.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Adobe Commerce 0 <= 2.4.4-p16

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.