Cyber & AI intelligence
Wasteland.
Briefs indexed2884
Issues29
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-71362 2026-09-24

CVE-2026-71362: Adobe Commerce and Magento Authorization Flaw Under Active Exploitation

"CISA has added CVE-2026-71362, a critical incorrect authorization flaw in Adobe Commerce and Magento Open Source, to its Known Exploited Vulnerabilities catalog, confirming active exploitation."

CISA has added CVE-2026-71362, a critical incorrect authorization flaw in Adobe Commerce and Magento Open Source, to its Known Exploited Vulnerabilities catalog, confirming active exploitation.

What Is It

CVE-2026-71362 is an incorrect authorization vulnerability (CWE-863) in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe's description says it can lead to privilege escalation, letting an attacker "gain elevated access to sensitive resources." Exploitation does not require user interaction.

NVD published the CVE on 2026-08-11. The Adobe PSIRT CVSS 3.1 score is 9.1 (Critical), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. That means the flaw is exploitable over the network, with low attack complexity and no privileges or user interaction required. Confidentiality and integrity impact are high, and there is no availability impact.

Why It Matters

CISA added the CVE to the KEV catalog on 2026-09-24, confirming that it is being exploited in the wild. CISA's SSVC assessment rates exploitation as active, the flaw as automatable, and the technical impact as total. KEV lists known ransomware campaign use as "Unknown."

CISA has also flagged this entry for forensic triage. Organizations covered by the directive should follow CISA's Forensics Triage Requirements as well as patching. The federal remediation deadline is 2026-09-27, three days after the KEV listing.

What's Vulnerable

According to Adobe's data in NVD:

Note: for Adobe Commerce 2.4.4 through 2.4.8, the NVD record lists the "-2026-aug" builds as both the upper bound of the affected range and as unaffected. Check Adobe bulletin APSB26-92 to confirm the exact fixed build for your release line.

Patch Status

NVD lists these builds as unaffected:

CISA required action: apply mitigations according to vendor instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance. If mitigations are unavailable, stop using the product. Stakeholders are responsible for evaluating each asset's internet exposure. Due date: 2026-09-27.

Sources