On 24 September CISA added CVE-2026-71362 to the KEV catalogue: incorrect authorisation in Adobe Commerce and Magento that can lead to privilege escalation without user action. The NVD record dates from 11 August. Adobe's bulletin did not open when we checked, so the facts rest on CISA and NVD.
- CVE-2026-71362 scores 9.1 on CVSS from Adobe and requires no user action.
- The deadline for US federal agencies is 27 September, three days after it entered the catalogue.
- NVD points to Adobe's bulletin APSB26-92; per NVD, Adobe Commerce, Adobe Commerce B2B and Magento Open Source are affected.
A Magento shop not updated per Adobe's bulletin is, as of today, on a list someone is already using.
The hole has been public since mid-August. What changed on 24 September is that CISA now has confirmation of real attacks.
What to do
Open the admin panel and check the version. Then open bulletin APSB26-92 from your own browser and compare. If your version is among the affected ones, you update right away.
Incorrect authorisation here means someone seeing or changing sensitive resources in the shop that they should not. No password, no click on your side.
If you maintain other people's Magento shops, today you do not wait for the client to ask. You update and write to tell them it is done.