Non-applicable security vulnerabilities
The Commerce+ team has evaluated the following security vulnerabilities identified within the Commerce+ stack and determined there is no impact to default deployments.
Vulnerabilities are grouped by assessment date.
July 29, 2026
A number of software vulnerabilities that have been identified do not apply to Commerce+.| CVE(s) | Applicable containers |
|---|---|
| CVE-2026-33701 | Elasticsearch Ingest server (ingest-app) |
| CVE-2026-33701 | Elasticsearch Query server (query-app) |
| CVE-2024-38828, CVE-2024-38820, CVE-2026-33701, CVE-2026-41842, CVE-2026-41845 , CVE-2026-41850 ,CVE-2026-41849, CVE-2022-46337, CVE-2026-47762, CVE-2026-47761, CVE-2026-47759 | Transaction server (ts-app) |
| CVE-2024-38828, CVE-2024-38820, CVE-2026-47762, CVE-2026-47761, CVE-2026-47759 |
Utility server
(ts-utils) |
| CVE-2026-33701, CVE-2026-2332, CVE-2026-2332, CVE-2025-11143, CVE-2024-6763, CVE-2026-44825, | Search server
(search-app) |
| CVE-2026-33701 | Cache Manager
(cache-app) |
| CVE-2026-33701 | Orchestration container
(orchestration-app) |
| CVE-2025-37731, CVE-2025-68390, CVE-2025-37727, CVE-2026-10532 , CVE-2024-52980 | Must-Gather server
(mustgather-app) |
| CVE-2026-27903, CVE-2026-27904, CVE-2026-26996, CVE-2026-48815, CVE-2026-9496, CVE-2026-29786, CVE-2026-31802, CVE-2026-53655, CVE-2026-13149, CVE-2026-33750, | Next.js store server
(nextjs-app) |
| CVE-2026-33701 | XC Server
(xc-app) |