HIGHVulnerability
Verified
Global

CISA KEV: Adobe Commerce and Magento — Adobe Commerce and Magento Incorrect Authorization Vulnerability

·Source: CISA KEV

Updated:

Executive Summary

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Analysis

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. Added to CISA Known Exploited Vulnerabilities catalog on 2026-09-24. Remediation due: 2026-09-27.

Indicators of Compromise (1)

CVE (1)
CVE-2026-71362
Source Attribution

Originally published by CISA KEV on Sep 24, 2026. Verified by: CISA.

Related Threats