PatchSiren cyber security CVE debrief
CVE-2026-34651 Adobe CVE debrief
CVE-2026-34651 is a high-severity availability issue in Adobe Commerce and Commerce B2B. According to Adobe’s advisory and the NVD record, an attacker can exhaust system resources over the network without user interaction, leading to application denial-of-service. The issue is classified as CWE-400, Uncontrolled Resource Consumption.
- Vendor
- Adobe
- Product
- Commerce
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-08-28
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-08-28
Who should care
Organizations running Adobe Commerce or Adobe Commerce B2B, especially teams responsible for internet-facing storefronts, uptime, and patch management. Administrators, incident responders, and hosting providers should prioritize review because the flaw is remotely reachable and affects availability.
Technical summary
The NVD record lists CVSS 3.1 vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, reflecting a network-accessible, low-complexity issue with no privileges or user interaction required and high availability impact. Adobe and NVD map the weakness to CWE-400. The affected scope includes Adobe Commerce versions up through 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17, and earlier, plus Commerce B2B releases covered by the vendor/NVD CPE ranges.
Defensive priority
High. The vulnerability is remotely exploitable, requires no user interaction, and can cause application denial-of-service in commerce platforms where uptime directly affects business operations.
Recommended defensive actions
- Review Adobe PSIRT advisory APSB26-49 for the vendor’s fixed release guidance.
- Prioritize patching Adobe Commerce and Commerce B2B instances that match the affected versions in the advisory and NVD record.
- Inventory exposed Commerce deployments and confirm whether any production or staging systems fall within the affected version ranges.
- Monitor for abnormal resource usage and application instability while remediation is being scheduled.
Evidence notes
This debrief is based only on the supplied NVD record and Adobe vendor advisory reference. NVD identifies the issue as analyzed, with an official Adobe reference (APSB26-49), CVSS 7.5 High, and CWE-400. The provided CPE criteria show affected Adobe Commerce and Commerce B2B versions, including Commerce 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, and 2.4.4-p17 and earlier. Published and modified timestamps are taken from the supplied CVE/timeline fields.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-34651 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-34651
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-34651 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-34651
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://helpx.adobe.com/security/products/magento/apsb26-49.html
[email protected] - Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.