we_are_coded.by CODE · The world, decoded
БГ
CISA

A hole in Adobe Commerce and Magento entered the catalogue of actively exploited vulnerabilities

CVE-2026-71362 (NVD, with the CISA KEV section) · event date: 24 September 2026Security

On 24 September CISA added CVE-2026-71362 to the KEV catalogue: incorrect authorisation in Adobe Commerce and Magento that can lead to privilege escalation without user action. The NVD record dates from 11 August. Adobe's bulletin did not open when we checked, so the facts rest on CISA and NVD.

In short
  • CVE-2026-71362 scores 9.1 on CVSS from Adobe and requires no user action.
  • The deadline for US federal agencies is 27 September, three days after it entered the catalogue.
  • NVD points to Adobe's bulletin APSB26-92; per NVD, Adobe Commerce, Adobe Commerce B2B and Magento Open Source are affected.
Checked on1 October 2026Responsible editorTsvetelin IvanovHow we workMethod · Corrections

A Magento shop not updated per Adobe's bulletin is, as of today, on a list someone is already using.

The hole has been public since mid-August. What changed on 24 September is that CISA now has confirmation of real attacks.

The facts: on 24 September 2026 CISA added CVE-2026-71362 - incorrect authorisation in Adobe Commerce and Magento - to its Known Exploited Vulnerabilities (KEV) catalogue, with a deadline of 27 September for US federal agencies. According to the NVD description, the vulnerability can lead to privilege escalation and access to sensitive resources without any user action; Adobe rates it 9.1 (critical) on CVSS 3.1. The NVD record was published on 11 August 2026 and points to APSB26-92 as the vendor bulletin; NVD lists versions of Adobe Commerce, Adobe Commerce B2B and Magento Open Source as affected. The Adobe bulletin page returned an access denied error when we checked, so the fixed versions have not been verified first-hand.

What to do

Open the admin panel and check the version. Then open bulletin APSB26-92 from your own browser and compare. If your version is among the affected ones, you update right away.

Incorrect authorisation here means someone seeing or changing sensitive resources in the shop that they should not. No password, no click on your side.

A patch you still have not installed is an invitation with a date on it.

If you maintain other people's Magento shops, today you do not wait for the client to ask. You update and write to tell them it is done.

The visual is generated code art. No third-party images.
Follow usFacebookLinkedIn
Official primary sources
→CVE-2026-71362 (NVD, with the CISA KEV section)→CISA: Known Exploited Vulnerabilities Catalog→Adobe Security Bulletin APSB26-92 (did not open when checked)
Original: https://wearecoded.com/en/articles/adobe-commerce-magento-dupka-kev.html
ShareFacebookXLinkedInTelegramWhatsApp
← Back to all news