Home · Wiki · Vulnerabilities & CVEs
type: cve · created: 2026-09-25 · updated: 2026-09-25 · tags: [cve, adobe, magento, commerce, privilege-escalation, kev, exploited] · confidence: high · severity: critical · affected_sectors: [retail, technology, finance] · au_impact: true

CVE-2026-71362 is a CVSS 3.1 9.1 incorrect-authorization vulnerability in Adobe Commerce and Magento Open Source that results in privilege escalation, allowing an attacker to gain elevated access to sensitive resources. Exploitation does not require user interaction.

CISA added it to the Known Exploited Vulnerabilities catalog on 24 September 2026. The flaw is the same one ASD's Australian Cyber Security Centre rated critical on 9 September 2026, when it warned of active exploitation in Adobe Commerce and Magento Open Source — so the KEV addition converts a national alert into a US federal remediation obligation rather than disclosing a new defect.

Details

Attribute Detail
CVE CVE-2026-71362
CVSS 9.1 (NVD, CVSS 3.1) — Critical
Vendor / product Adobe Commerce and Magento Open Source
Type Incorrect authorization → privilege escalation
User interaction None required
Status In CISA KEV as of 24 September 2026; ACSC critical alert, 9 September 2026
Reported 24 September 2026 (KEV addition)

Mitigation

Patch to the vendor's fixed release. Because the mechanism is an authorization failure rather than a memory-safety bug, there is no configuration workaround that reliably closes it, and the absence of a user-interaction requirement means the attack surface is the storefront or admin endpoint itself. Merchants should also treat prior exposure as a possibility: the ACSC's 9 September alert and the subsequent KEV listing together indicate exploitation predates the US catalogue entry, so a post-patch review of administrative account creation and privilege changes is warranted.