Adobe Commerce CVE-2026-71362: Critical Flaw Exploited, Patch Now

A critical incorrect-authorization bug in Adobe Commerce and Magento Open Source is being actively exploited to hijack customer sessions. CISA set a September 27 federal patch deadline.

Adobe's corporate logo, showing the red angular 'A' icon beside the Adobe wordmark on a white background
Adobe's corporate logo. Image: Adobe.

CVE-2026-71362, a critical "incorrect authorization" vulnerability affecting Adobe Commerce, Adobe Commerce B2B and Magento Open Source, is being actively exploited against live online stores. The flaw, rated 9.1 out of 10 on the CVSS 3.1 scale, lets an attacker hijack another shopper's authenticated session without logging in, without an existing account and without any admin privileges — exposing that customer's personal data, order history, saved addresses and stored payment information. Adobe patched the bug on August 11, 2026 through security bulletin APSB26-92. The Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-71362 to its Known Exploited Vulnerabilities (KEV) catalog on September 24, 2026, giving federal civilian agencies until September 27, 2026 to remediate it. Any store still running an unpatched release should treat this as an emergency change, not a maintenance-window item.

CVE-2026-71362 at a glance

  • Vulnerability: Incorrect Authorization (CWE-863)
  • CVSS 3.1 score: 9.1 (Critical) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
  • Affected products: Adobe Commerce, Adobe Commerce B2B, Magento Open Source (2026-jul releases and earlier)
  • Fixed in: The corresponding 2026-aug release of each product line
  • Adobe bulletin: APSB26-92, published August 11, 2026, Priority 2
  • CISA KEV added: September 24, 2026 — federal deadline September 27, 2026
  • Authentication required to exploit: No

What happened

On August 11, 2026, Adobe published security bulletin APSB26-92, resolving seven vulnerabilities across Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Five of the seven were rated Critical, and the most severe by far was CVE-2026-71362, an incorrect authorization flaw that Adobe scored 9.1 and classified with a "privilege escalation" impact. At the time of release, Adobe's bulletin stated the company was "not aware of any exploits in the wild for any of the issues addressed" and assigned the update an overall Priority 2 rating.

That changed within weeks. By late September, CISA had evidence of active exploitation and added CVE-2026-71362 to its Known Exploited Vulnerabilities catalog on September 24, 2026, describing it as a vulnerability that "could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction." Under Binding Operational Directive BOD 26-04, that listing carries a hard remediation deadline of September 27, 2026 for U.S. federal civilian executive branch agencies running the affected software. Merchants outside the federal government aren't bound by that deadline, but the KEV listing is effectively a public confirmation that working exploit activity exists against unpatched Adobe Commerce and Magento installations today.

Why this flaw is so dangerous for online stores

Adobe Commerce and Magento Open Source power storefronts that store exactly the kind of data attackers want most: names, addresses, order histories, loyalty balances and tokenized or saved payment details tied to real customer accounts. A vulnerability that lets an outsider step into any logged-in customer's session — with no password, no prior account and no click required from the victim — turns every active shopping session on the storefront into a potential target. Unlike an admin-panel compromise, which at least requires an attacker to find and target privileged credentials, this class of bug can in principle be pointed at the general customer population of a store, which on a large retailer can mean tens or hundreds of thousands of accounts.

The CVSS vector Adobe published — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N — spells out why the 9.1 score is justified: the attack is reachable over the network (AV:N), requires low complexity (AC:L), needs no privileges (PR:N) and no user interaction (UI:N), and carries high confidentiality and integrity impact (C:H/I:H). The absence of an availability impact (A:N) means this isn't a denial-of-service bug; it's a data-exposure and account-integrity bug, which for an e-commerce platform subject to PCI DSS and consumer privacy regulation is arguably worse than downtime.

Inside CVE-2026-71362: what "incorrect authorization" means here

Adobe's own classification places CVE-2026-71362 under CWE-863, Incorrect Authorization — a category covering cases where software performs an action on behalf of a user but fails to properly verify that the user is actually authorized to have that action performed for them. Adobe's bulletin does not publish exploit-level technical detail, which is standard practice for an actively weaponizable bug, and the National Vulnerability Database entry mirrors Adobe's language closely, describing the issue only as one where "an attacker could leverage this vulnerability to gain elevated access to sensitive resources."

Independent researchers who examined the patch have described the underlying issue in more concrete terms: a customer-session handling defect that allows an authenticated request to be re-pointed at a different customer's account identifier, effectively letting one shopper's session act as another shopper's session. Sansec, a firm that focuses on Magento and Adobe Commerce security and operates a web application firewall for the platform, has reported that it began blocking exploitation attempts against CVE-2026-71362 against customer stores. Those details come from third-party research rather than from Adobe or CISA directly, so they should be read as reported observations about how the bug behaves in practice, not as an official technical disclosure from Adobe.

What is confirmed, directly from Adobe's bulletin and the CVE record, is the practical effect: no authentication is required to exploit the bug, no admin privileges are needed, and the impact is scoped to privilege escalation with high confidentiality and integrity consequences — consistent with an attacker being able to read and potentially act within another customer's account context.

Affected Adobe Commerce, Commerce B2B and Magento Open Source versions

Adobe's bulletin lists the vulnerable version ranges as every "2026-jul" release and earlier across the current supported branches, with the fix delivered in the matching "2026-aug" release. The table below reflects the version matrix published in APSB26-92.

ProductVulnerable versionsFixed versionPlatform
Adobe Commerce2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul, 2.4.5-2026-jul, 2.4.4-2026-jul and earlierMatching 2.4.x-2026-aug releaseAll
Adobe Commerce B2B1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlierMatching 1.x-2026-aug releaseAll
Magento Open Source2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlierMatching 2.4.x-2026-aug releaseAll

Because CVE-2026-71362 was patched alongside six other vulnerabilities in the same bulletin — including two other Critical-rated incorrect-authorization bugs, CVE-2026-48415 and CVE-2026-48416 — Adobe's guidance is to move straight to the August 2026 release for your product line rather than attempt to cherry-pick a single fix. Store operators on Adobe-managed Commerce Cloud infrastructure should confirm with Adobe or their hosting partner whether the update has already been applied to their environment, since cloud-hosted instances are sometimes patched on a rolling schedule.

Why CISA added it to the KEV catalog

CISA's Known Exploited Vulnerabilities catalog exists specifically to flag vulnerabilities for which there is reasonable evidence of real-world exploitation, as distinct from the much larger pool of vulnerabilities that are merely theoretically exploitable. The KEV entry for CVE-2026-71362 lists a dateAdded of September 24, 2026 and a dueDate of September 27, 2026 — a notably short three-day remediation window that signals CISA considers the exploitation risk severe and the patch straightforward enough that agencies have little excuse to delay. The entry's required action directs agencies to apply Adobe's fix in line with BOD 26-04, CISA's directive for prioritizing security updates based on risk, or to discontinue use of the product if a mitigation isn't available.

Adobe Commerce and Magento join a growing list of widely deployed enterprise and web platforms that have landed on the KEV catalog this year after active exploitation was confirmed post-patch, a pattern also seen recently with the WordPress remote code execution flaw tracked as CVE-2026-87902 and with Citrix NetScaler's CVE-2026-88771 and CVE-2026-88772. In each case, attackers moved to weaponize the bug within weeks of the vendor's advisory, underscoring how quickly a patch-now window can close once technical details and proof-of-concept exploits start circulating.

What's being reported about exploitation attempts

Beyond CISA's KEV listing, Adobe has not published a detailed account of how attackers are using CVE-2026-71362 in the wild, and the company's bulletin explicitly noted it had no evidence of exploitation as of the August 11 publication date. The exploitation activity that led to the September 24 KEV addition has been attributed by CISA only in general terms, consistent with its standard KEV entry format.

Sansec, which monitors e-commerce platforms for compromise and has previously been first to flag several high-profile Magento supply-chain and skimming campaigns, has said its own protective tooling began intercepting exploitation attempts against the vulnerability. That claim comes from Sansec's own reporting rather than from Adobe or CISA, and the scale, targeting and success rate of those attempts have not been independently verified by this publication. Store operators should treat it as a strong signal that scanning and exploitation activity is already underway, not as a precise measurement of how many stores have been breached.

Adobe's Priority 2 rating, explained

Adobe assigned APSB26-92 an overall Priority rating of 2. In Adobe's own scale, Priority 1 is reserved for vulnerabilities with a higher risk of being exploited, where Adobe recommends an emergency, out-of-cycle update; Priority 2 covers vulnerabilities in a product that has historically been a target, where Adobe recommends installing the update within 30 days. Adobe Commerce and Magento have a long history of real-world exploitation, including mass automated scanning for known flaws and supply-chain style skimmer injections, which is part of why Adobe treats updates to the platform with elevated urgency even absent evidence of exploitation at disclosure time.

The KEV listing effectively overtakes that original 30-day guidance: once a flaw is confirmed as exploited, the operative deadline becomes "as soon as possible," not the vendor's original advisory window. That is the same dynamic seen with other recently KEV-listed network and application vulnerabilities, including the FortiMail flaw tracked as CVE-2026-104286, where a vendor's initial risk rating was superseded within weeks by confirmed in-the-wild attacks.

What to do next

If your organization runs Adobe Commerce, Adobe Commerce B2B or Magento Open Source, treat this as an immediate patching priority rather than routine maintenance:

  • Identify every affected instance. Inventory all Adobe Commerce, Commerce B2B and Magento Open Source deployments, including staging, development and any customer-facing storefronts, and record the exact version string (for example, 2.4.7-2026-jul) running on each.
  • Apply the 2026-aug release. Update each affected instance to the matching 2.4.x-2026-aug (Commerce/Magento) or 1.x-2026-aug (Commerce B2B) release described in APSB26-92. Because the bulletin bundles fixes for seven vulnerabilities, apply the full release rather than attempting an isolated patch.
  • Confirm cloud-hosted patch status. If your store runs on Adobe Commerce Cloud or a managed hosting provider, verify directly with Adobe or your hosting partner that the August 2026 update has been applied to your environment and is not pending a scheduled maintenance window.
  • Force-expire active customer sessions after patching. Because the vulnerability concerns session and identity handling, invalidate existing customer sessions once the update is applied so that any sessions established before the patch cannot be leveraged afterward.
  • Review account activity for signs of compromise. Audit customer account logs for anomalous session or account-switching behavior, unexpected changes to saved addresses or payment methods, and unusual order activity in the weeks surrounding the August disclosure and September KEV listing.
  • Notify affected customers if compromise is confirmed. Given the exposure covers personal data, order history and saved payment and address information, confirmed account-takeover activity may trigger breach-notification obligations depending on your jurisdiction and the data involved.
  • Track Adobe's bulletin for updates. Adobe periodically revises published bulletins as more information becomes available; APSB26-92 was already updated once, on August 18, 2026, after its initial publication.

Federal civilian agencies subject to CISA's KEV catalog should treat the September 27, 2026 date as a hard compliance deadline under BOD 26-04. Every other organization running the affected software should still move at that same pace: a CVSS 9.1 flaw with no authentication requirement, now listed as actively exploited, is about as clear a "patch immediately" signal as a vendor advisory gets.

Frequently asked questions

What is CVE-2026-71362? It's a critical incorrect authorization vulnerability (CWE-863) in Adobe Commerce, Adobe Commerce B2B and Magento Open Source, scored 9.1 on CVSS 3.1, that can let an attacker gain elevated access to another customer's account and data without authentication.

Is CVE-2026-71362 being actively exploited? Yes. CISA added it to its Known Exploited Vulnerabilities catalog on September 24, 2026, confirming evidence of real-world exploitation, with a remediation deadline of September 27, 2026 for federal agencies.

Which versions are affected? Adobe Commerce, Adobe Commerce B2B and Magento Open Source releases from the 2026-jul patch level and earlier are vulnerable. The fix ships in each product line's corresponding 2026-aug release.

Do I need admin access for an attacker to exploit this? No. Adobe's bulletin states the flaw requires no authentication and no admin privileges to exploit, which is part of why it was rated 9.1.

What should I do if I can't patch immediately? Adobe's bulletin does not list a workaround for CVE-2026-71362, so the only vendor-confirmed remediation is upgrading to the 2026-aug release. If an immediate upgrade genuinely isn't possible, CISA's KEV guidance says to apply vendor mitigations or discontinue use of the product.

Where can I read Adobe's official advisory? Adobe's full technical bulletin, including the complete version matrix and the six other vulnerabilities fixed in the same update, is published as APSB26-92.

Frequently asked questions

What is CVE-2026-71362?

It's a critical incorrect authorization vulnerability (CWE-863) in Adobe Commerce, Adobe Commerce B2B and Magento Open Source, scored 9.1 on CVSS 3.1, that can let an attacker gain elevated access to another customer's account and data without authentication.

Is CVE-2026-71362 being actively exploited?

Yes. CISA added it to its Known Exploited Vulnerabilities catalog on September 24, 2026, confirming evidence of real-world exploitation, with a remediation deadline of September 27, 2026 for federal agencies.

Which versions are affected?

Adobe Commerce, Adobe Commerce B2B and Magento Open Source releases from the 2026-jul patch level and earlier are vulnerable. The fix ships in each product line's corresponding 2026-aug release.

Do I need admin access for an attacker to exploit this?

No. Adobe's bulletin states the flaw requires no authentication and no admin privileges to exploit, which is part of why it was rated 9.1.

What should I do if I can't patch immediately?

Adobe's bulletin does not list a workaround for CVE-2026-71362, so the only vendor-confirmed remediation is upgrading to the 2026-aug release. If an immediate upgrade genuinely isn't possible, CISA's KEV guidance says to apply vendor mitigations or discontinue use of the product.

Where can I read Adobe's official advisory?

Adobe's full technical bulletin, including the complete version matrix and the six other vulnerabilities fixed in the same update, is published as APSB26-92 on Adobe's helpx.adobe.com security pages.

Sources

More on Adobe Commerce →Adobe CommerceMagento Open SourceCVE-2026-71362CISA KEVPatch Now
Sana Qureshi
Written bySana Qureshi

Sana Qureshi runs the security and privacy desk. She reports on actively exploited vulnerabilities, vendor patches and data breaches, and covers the password managers, VPNs and authentication tools readers use to protect themselves. Her alerts cite vendor advisories, CISA and the CVE record directly.

More from Security & Privacy

See all