DIRAS TAKE
Urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a September 27, 2026 remediation deadline, making rapid action imperative; treat internet-facing Adobe Commerce and Magento instances as high priority.
What is CVE-2026-71362?
Remote attackers can escalate privileges on Adobe Commerce and Magento by exploiting an incorrect authorization flaw in the web application, tracked as CVE-2026-71362. Affected products include Adobe Commerce 2.x (2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier), Adobe Commerce B2B 1.x (1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier), and Magento Open Source 2.x (2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier). Exploitation requires only network access and does not need authentication or user interaction.
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Which versions of Adobe Commerce and Magento are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| Adobe Commerce 2.x | 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier | |
| Adobe Commerce B2B 1.x | 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier | |
| Magento Open Source 2.x | 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier |
Is CVE-2026-71362 being exploited?
CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog on 2026-09-24 and US federal agencies must address it by 2026-09-27. Public exploit code is available.
How to fix CVE-2026-71362
- Isolate or restrict internet exposure of Adobe Commerce and Magento instances until mitigations are applied.
- Follow Adobe's vendor guidance and mitigations immediately; if a patch is unavailable, implement recommended configuration hardening.
- Monitor logs and investigate anomalous admin or privilege-related activity for signs of compromise.
- Apply network-level controls (WAF, IP allowlists) to block exploit attempts where feasible and prioritize replacement or removal of affected deployments per CISA guidance.
Frequently asked questions
Is CVE-2026-71362 being actively exploited?
Yes; CISA added CVE-2026-71362 to its Known Exploited Vulnerabilities catalog on 2026-09-24 and public exploit code is available.
Which Adobe Commerce and Magento versions are affected by CVE-2026-71362?
Adobe Commerce 2.x (2.4.9-2026-jul and earlier in the listed branch), Adobe Commerce B2B 1.x (1.5.3-2026-jul and earlier in the listed branch), and Magento Open Source 2.x (2.4.9-2026-jul and earlier in the listed branch) are affected.
Is there a patch for CVE-2026-71362?
No vendor-fixed versions are listed in the supplied facts; follow Adobe's guidance for available mitigations until a patch is released.
Does CVE-2026-71362 require authentication?
No; the vulnerability can be exploited over the network without authentication or user interaction against affected Adobe Commerce and Magento releases.
References
- nvd.nist.gov/vuln/detail/CVE-2026-71362
- cve.org/CVERecord?id=CVE-2026-71362
- cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-71362
- helpx.adobe.com/security/products/magento/apsb26-92.html
- All Adobe CVEs on CVE Radar
- CVEs published in September 2026