VDB

CVE-2026-27278

CVE-2026-27278 PUBLISHED CVSS 7.800000190734863 HIGH

Adobe Commerce versions 2.4.9-alpha3, 2.4.8-p3, 2.4.7-p8, 2.4.6-p13, 2.4.5-p15, 2.4.4-p16 and earlier are affected by an Improper Input Validation vulnerability that could lead to application denial-of-service. An attacker could exploit this vulnerability by providing specially crafted input, causing limited impact to application availability. Exploitation of this issue does not require user interaction.

EPSS 0.04% · 14.1th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.04%
14.1th percentile

Affected Products

VendorProductVersions
adobeacrobat_reader_dc0
adobeacrobat_dc0
adobeacrobat24.001.20604
AdobeAcrobat Reader0
AdobeAdobe Commerce0

Timeline

  • Mar 10, 2026 CVE Published
  • Mar 11, 2026 EPSS Score
  • Mar 11, 2026 PoC Published
  • Mar 12, 2026 EPSS Score
  • Mar 12, 2026 CVE Updated
  • Mar 12, 2026 PoC Published
  • Mar 12, 2026 PoC Published
  • Mar 13, 2026 EPSS Score
  • Mar 14, 2026 EPSS Score
  • Mar 15, 2026 EPSS Score
  • Mar 16, 2026 EPSS Score
  • Mar 17, 2026 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›