CVE-2026-71362 actively exploited: Adobe Commerce and Magento Incorrect Authorization Vulnerability

CISA added CVE-2026-71362, an incorrect authorization in Adobe Commerce and Magento, to its Known Exploited Vulnerabilities catalogue. It could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Federal agencies must remediate by September 27, 2026.

Adobe Commerce and Magento contain an incorrect authorization flaw. Ciska asserts that this issue permits attackers to gain elevated access to sensitive resources. The exploit requires no user interaction to proceed. The severity of the actual damage remains uncertain until full triage is complete. The product identified within the dataset includes Adobe Commerce and Magento systems. Federal agencies hold the specific responsibility to manage these assets. Stakeholders must evaluate the internet exposure of each individual asset. No specific customer count was provided in the source material regarding the scale of exposure. Vendor instructions dictate the immediate application of mitigations. Compliance with CISA’s BOD 26-04 guiding principles is mandatory for all federal bodies. Cloud services require specific adherence to the patching guidelines outlined in that document. If mitigations prove unavailable, discontinuing use of the product becomes the required action. The deadline for federal remediation is September 27, 2026.