peter bassill · operator
$ cve CVE-2026-71362 JSON

CVE-2026-71362 KEV

9.1
CRITICAL · CVSS 3.1 · EPSS 87.5% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2026-09-27.

Description

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS87.51% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-863
On CISA KEVyes — remediate by 2026-09-27
Public exploitnone known
Published2026-08-11
Last modified2026-09-25

CISA KEV

NameAdobe Commerce and Magento Incorrect Authorization Vulnerability
Added2026-09-24
Due2026-09-27
Vendor / productAdobe / Commerce and Magento
Ransomware usenone reported

Affected (3)

VendorProduct
adobecommerce
adobecommerce b2b
adobemagento

References

→ the Explorer  ·  watch your stack  ·  NVD