CISA has added CVE-2026-71362, a critical incorrect authorization flaw in Adobe Commerce and Magento Open Source, to its Known Exploited Vulnerabilities catalog, confirming active exploitation.
What Is It
CVE-2026-71362 is an incorrect authorization vulnerability (CWE-863) in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe's description says it can lead to privilege escalation, letting an attacker "gain elevated access to sensitive resources." Exploitation does not require user interaction.
NVD published the CVE on 2026-08-11. The Adobe PSIRT CVSS 3.1 score is 9.1 (Critical), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N. That means the flaw is exploitable over the network, with low attack complexity and no privileges or user interaction required. Confidentiality and integrity impact are high, and there is no availability impact.
Why It Matters
CISA added the CVE to the KEV catalog on 2026-09-24, confirming that it is being exploited in the wild. CISA's SSVC assessment rates exploitation as active, the flaw as automatable, and the technical impact as total. KEV lists known ransomware campaign use as "Unknown."
CISA has also flagged this entry for forensic triage. Organizations covered by the directive should follow CISA's Forensics Triage Requirements as well as patching. The federal remediation deadline is 2026-09-27, three days after the KEV listing.
What's Vulnerable
According to Adobe's data in NVD:
- Adobe Commerce: versions up to and including 2.4.9-2026-jul, plus earlier 2.4.x release lines back to 2.4.4. NVD's CPE data also includes Commerce versions below 2.4.4.
- Adobe Commerce B2B: 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier.
- Magento Open Source: 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier.
Note: for Adobe Commerce 2.4.4 through 2.4.8, the NVD record lists the "-2026-aug" builds as both the upper bound of the affected range and as unaffected. Check Adobe bulletin APSB26-92 to confirm the exact fixed build for your release line.
Patch Status
NVD lists these builds as unaffected:
- Adobe Commerce: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug
- Adobe Commerce B2B: 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug, 1.3.3-2026-aug
- Magento Open Source: 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug
CISA required action: apply mitigations according to vendor instructions, in line with BOD 26-04 (Prioritizing Security Updates Based on Risk) and CISA's Forensics Triage Requirements. For cloud services, follow the applicable BOD 26-04 guidance. If mitigations are unavailable, stop using the product. Stakeholders are responsible for evaluating each asset's internet exposure. Due date: 2026-09-27.