Vulnerability  ·  2026-09-26

KEV: Adobe Commerce/Magento incorrect authorization exploited (CVE-2026-71362)

VulnerabilityMedium impactGlobalCVE-2026-71362
CISA added CVE-2026-71362 to the KEV catalog on 24 Sept 2026 (Adobe Commerce/Magento authorization flaw, APSB26-92) with confirmed exploitation.
Elevated-privilege access to the commerce platform also grants access to the AI personalization/chat components and customer data they process - patch per KEV timeline.
Incorrect authorization allowing an attacker to gain elevated access to sensitive resources without user interaction; CISA KEV addition 24 Sept 2026 confirms in-the-wild exploitation.
Adobe Commerce and Magento (incorrect authorization, CWE-863)
Apply Adobe security update APSB26-92 immediately; follow BOD 26-04 guidance.
CISA KEV catalogAdobe APSB26-92
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →