Skip to content

CVE-2026-71362

Adobe Commerce incorrect authorization allows unauthenticated privilege escalation (CVE-2026-71362)

Critical 9.1 KEV Published · Updated

Adobe Commerce, Adobe Commerce B2B and Magento Open Source are affected by an incorrect authorization vulnerability (CVE-2026-71362) with a critical CVSS 9.1 score. CISA lists it as actively exploited. Apply the August 2026 security updates before 27 September 2026.

What happened

Adobe Commerce is affected by an incorrect authorization weakness (CWE-863) that can be exploited for privilege escalation. An attacker can reach it over the network without credentials and without user interaction, then use the elevated access to read or alter sensitive resources. The CVSS 3.1 vector assigns high confidentiality and integrity impact and no availability impact.

CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog on 24 September 2026, with a due date of 27 September 2026. CISA's SSVC assessment marks exploitation as active and automatable, with total technical impact. No vendor statement is included in the information provided.

Who is affected

The affected products are Adobe Commerce, Adobe Commerce B2B and Magento Open Source. These are internet-facing e-commerce platforms, commonly holding customer and payment data.

Adobe lists these affected versions: for Adobe Commerce, up to and including 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug; for Adobe Commerce B2B, up to and including 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul; and for Magento Open Source, up to and including 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul.

What to do now

  1. Apply the August 2026 security updates. Adobe lists these fixed versions: Adobe Commerce 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug; Adobe Commerce B2B 1.5.3-2026-aug, 1.5.2-2026-aug, 1.4.2-2026-aug, 1.3.4-2026-aug and 1.3.3-2026-aug; and Magento Open Source 2.4.9-2026-aug, 2.4.8-2026-aug, 2.4.7-2026-aug and 2.4.6-2026-aug.
  2. Prioritise this update for CISA's KEV due date, 27 September 2026.
  3. If you cannot patch immediately, restrict network access to affected storefronts and admin interfaces and monitor for unexpected high-privilege accounts until the update is applied.

Beyond the patch

Because CISA has already listed this as actively exploited, the immediate priority is to patch and then find out whether the flaw has been used in your environment. Our Managed Detection & Response can help investigate whether exploitation has occurred, while Virtual CISO Services can help identify any internet-facing Commerce or Magento deployments that should have been patched first. The aim is to close the exposure before the next one arrives.

Affected and fixed versions

ProductAffectedFixed in
Adobe Commerce– ≤ 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug2.4.9-2026-aug
2.4.8-2026-aug
2.4.7-2026-aug
2.4.6-2026-aug
2.4.5-2026-aug
2.4.4-2026-aug
B2B 1.5.3-2026-aug
B2B 1.5.2-2026-aug
B2B 1.4.2-2026-aug
B2B 1.3.4-2026-aug
B2B 1.3.3-2026-aug
Adobe Commerce B2B– ≤ 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul1.5.3-2026-aug
1.5.2-2026-aug
1.4.2-2026-aug
1.3.4-2026-aug
1.3.3-2026-aug
Magento Open Source– ≤ 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul2.4.9-2026-aug
2.4.8-2026-aug
2.4.7-2026-aug
2.4.6-2026-aug

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.