CVE-2026-71362 KEV
9.1
CRITICAL · CVSS 3.1 · EPSS 87.5% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2026-09-27.
Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 87.51% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-863 |
| On CISA KEV | yes — remediate by 2026-09-27 |
| Public exploit | none known |
| Published | 2026-08-11 |
| Last modified | 2026-09-25 |
CISA KEV
| Name | Adobe Commerce and Magento Incorrect Authorization Vulnerability |
|---|---|
| Added | 2026-09-24 |
| Due | 2026-09-27 |
| Vendor / product | Adobe / Commerce and Magento |
| Ransomware use | none reported |
Affected (3)
| Vendor | Product |
|---|---|
| adobe | commerce |
| adobe | commerce b2b |
| adobe | magento |
References
→ the Explorer · watch your stack · NVD