CVE-2026-71362 — Adobe Commerce and Magento Incorrect Authorization Vulnerability

CVE-2026-71362 in Adobe Commerce and Magento is listed in the CISA Known Exploited Vulnerabilities catalog (added 2026-09-24). Required action, remediation due date, ransomware association, EPSS score and vendor advisories.

Exploitation status

CVE-2026-71362 is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added 2026-09-24. Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Advisory facts

Vendor or project
Adobe
Affected product
Commerce and Magento
Added to CISA KEV
2026-09-24
US federal remediation due date
2026-09-27
Ransomware association
Unknown
EPSS score
—
Weakness (CWE)
CWE-863

Remediation: the required action

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Wording published by CISA for this catalog entry. It is the baseline action, not a decision about your environment: whether this exposure matters for you depends on where the affected component runs, what it is exposed to and who owns it.

From advisory to a decision you can defend

A catalog entry tells you a vulnerability is being exploited somewhere. It does not tell you whether it matters in your estate, who owns the fix, or what evidence an auditor will ask for later. That is the work VulnTrek does: it takes findings from the tools you already run, decides which exposure actually matters, routes it to an owner, keeps remediation human-approved and retains the lineage as evidence.

Sourced from public upstream advisories (CISA KEV, ENISA EUVD, vendor PSIRTs) mirrored daily. Informational only — not a remediation decision, not legal advice, and the absence of a record is not evidence of safety.