Skip to content

Weekly roundup

Open-source business platforms, week 33 2026: one exploited Adobe Commerce flaw among seven CVEs

Critical 9.1 KEV Vendor: Open-source business platforms 7 CVEs in scope Published

Open-source business platforms week 33 of 2026: seven Adobe Commerce CVEs, including one exploited and KEV-listed incorrect authorisation flaw. Prioritise CVE-2026-71362 and apply the August 2026 Commerce, B2B and Magento Open Source updates.

The release at a glance

Adobe’s week 33 of 2026 release covers seven CVEs, all of them in the Adobe Commerce family; the same fixes apply to Adobe Commerce B2B and Magento Open Source. The severity breakdown is one critical, four high, one medium and one low, and Adobe has published fixed builds for every CVE in the release.

One item stands out: CVE-2026-71362 is listed in CISA's Known Exploited Vulnerabilities catalog and by ENISA EUVD as exploited, with an Incorrect Authorization weakness allowing privilege escalation without user interaction. CISA's due date is 27 September 2026. Adobe's advisory is at https://helpx.adobe.com/security/products/magento/apsb26-92.html.

What matters most

All seven CVEs sit within Adobe Commerce. The affected product list includes Adobe Commerce, Adobe Commerce B2B and Magento Open Source, so the same patch decision applies across the storefront and the open-source edition.

  • CVE-2026-71362 — Incorrect Authorization, critical with CVSS 3.1 9.1. Network attack, no privileges, no user interaction. A successful attacker can gain elevated access to sensitive resources. This is the only exploited item in the release, listed by CISA KEV and ENISA EUVD; CISA's due date is 27 September 2026. There is a separate advisory page on this site.
  • CVE-2026-48416 — Incorrect Authorization, high with CVSS 3.1 7.5. No privileges and no user interaction are required for unauthorized read access over the network, which makes this important for internet-facing storefronts. No active exploitation is listed.
  • CVE-2026-48415 — Incorrect Authorization, high with CVSS 3.1 7.6. A low-privileged attacker can bypass security measures for unauthorized read and write access, with limited disruption to availability.
  • CVE-2026-48413 — Stored XSS, high with CVSS 3.1 8.7. A low-privileged attacker can inject a script into form fields; the script runs in a victim's browser when the page is opened. Scope is changed.
  • CVE-2026-48414 — Stored XSS, high with CVSS 3.1 7.7. Similar stored XSS, but exploitation depends on conditions beyond the attacker's control.
  • CVE-2026-48411 — Incorrect Authorization, medium with CVSS 3.1 6.5. Requires high privileges and can lead to unauthorized write access.
  • CVE-2026-48412 — Incorrect Authorization, low with CVSS 3.1 2.7. Requires high privileges and can give limited elevated access to restricted resources.

Patch in this order

Patch in this order:

  1. Apply the August 2026 update for CVE-2026-71362 first. It is actively exploited, and CISA's due date is 27 September 2026. The fixed builds are Adobe Commerce 2.4.4-2026-aug, 2.4.5-2026-aug, 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug and 2.4.9-2026-aug; Adobe Commerce B2B 1.3.3-2026-aug, 1.3.4-2026-aug, 1.4.2-2026-aug, 1.5.2-2026-aug and 1.5.3-2026-aug; and Magento Open Source 2.4.6-2026-aug, 2.4.7-2026-aug, 2.4.8-2026-aug and 2.4.9-2026-aug.
  1. Next, treat CVE-2026-48416 as a priority on internet-facing storefronts. It requires no privileges and no user interaction, and gives unauthorized read access over the network.
  1. Cover the remaining high-severity items — CVE-2026-48415, CVE-2026-48413 and CVE-2026-48414 — in the same August update, especially where low-privileged accounts are common.
  1. Include CVE-2026-48411 and CVE-2026-48412 in the same patch window. They require high privileges and are lower risk, but the August build resolves them.

Beyond the patch

For a release like this, the trigger for action is one actively exploited issue, not the whole list. Managed Detection & Response can look for unexplained privilege changes or access to sensitive resources in Adobe Commerce, while Implementation & Assessment Services can test your storefront and hardening controls before and after the August 2026 update.

Every CVE in this release

CVEProductSeverity
CVE-2026-71362Adobe CommerceCritical 9.1 KEVAdvisory →
CVE-2026-48413Adobe CommerceHigh 8.7Advisory →
CVE-2026-48414Adobe CommerceHigh 7.7Advisory →
CVE-2026-48415Adobe CommerceHigh 7.6Advisory →
CVE-2026-48416Adobe CommerceHigh 7.5Advisory →
CVE-2026-48411Adobe CommerceMedium 6.5Advisory →
CVE-2026-48412Adobe CommerceLow 2.7Advisory →

References

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them.

Written with AI assistance from the sources above and checked automatically against them before publication.