Non-applicable security vulnerabilities

The Commerce+ team has evaluated the following security vulnerabilities identified within the Commerce+ stack and determined there is no impact to default deployments.

Vulnerabilities are grouped by assessment date.

July 29, 2026

A number of software vulnerabilities that have been identified do not apply to Commerce+.
CVE(s) Applicable containers
CVE-2026-33701 Elasticsearch Ingest server (ingest-app)
CVE-2026-33701 Elasticsearch Query server (query-app)
CVE-2024-38828, CVE-2024-38820, CVE-2026-33701, CVE-2026-41842, CVE-2026-41845 , CVE-2026-41850 ,CVE-2026-41849, CVE-2022-46337, CVE-2026-47762, CVE-2026-47761, CVE-2026-47759 Transaction server (ts-app)
CVE-2024-38828, CVE-2024-38820, CVE-2026-47762, CVE-2026-47761, CVE-2026-47759 Utility server (ts-utils)
CVE-2026-33701, CVE-2026-2332, CVE-2026-2332, CVE-2025-11143, CVE-2024-6763, CVE-2026-44825, Search server (search-app)
CVE-2026-33701 Cache Manager (cache-app)
CVE-2026-33701 Orchestration container (orchestration-app)
CVE-2025-37731, CVE-2025-68390, CVE-2025-37727, CVE-2026-10532 , CVE-2024-52980 Must-Gather server (mustgather-app)
CVE-2026-27903, CVE-2026-27904, CVE-2026-26996, CVE-2026-48815, CVE-2026-9496, CVE-2026-29786, CVE-2026-31802, CVE-2026-53655, CVE-2026-13149, CVE-2026-33750, Next.js store server (nextjs-app)
CVE-2026-33701 XC Server (xc-app)