• CISA KEV
  • EXPLOITED
  • PoC PUBLIC

CVE-2026-71362: pre-auth privilege escalation in Adobe Commerce and Magento

Remote attackers can escalate privileges on Adobe Commerce and Magento by exploiting an incorrect authorization flaw in the web application, tracked as CVE-2026-71362. Affected products include Adobe Commerce 2.x (2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier), Adobe Commerce B2B 1.x (1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier), and Magento Open Source 2.x (2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier). Exploitation requires only network access and does not need authentication or user interaction.

Published Updated Source: CVE Program, NVD, CISA KEV, FIRST EPSS, Vendor advisory

CVSS 3.1
9.1CRITICAL
EPSS
0.87507
CWE
CWE-863
KEV DUE DATE
PATCH
Not yet

DIRAS TAKE

Urgent: CISA added this vulnerability to its Known Exploited Vulnerabilities catalog with a September 27, 2026 remediation deadline, making rapid action imperative; treat internet-facing Adobe Commerce and Magento instances as high priority.

What is CVE-2026-71362?

Remote attackers can escalate privileges on Adobe Commerce and Magento by exploiting an incorrect authorization flaw in the web application, tracked as CVE-2026-71362. Affected products include Adobe Commerce 2.x (2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier), Adobe Commerce B2B 1.x (1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier), and Magento Open Source 2.x (2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier). Exploitation requires only network access and does not need authentication or user interaction.

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Which versions of Adobe Commerce and Magento are affected?

BRANCHAFFECTEDFIXED
Adobe Commerce 2.x2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug, 2.4.4-2026-aug and earlier
Adobe Commerce B2B 1.x1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul, 1.3.3-2026-jul and earlier
Magento Open Source 2.x2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul, 2.4.6-2026-jul and earlier

Is CVE-2026-71362 being exploited?

CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog on 2026-09-24 and US federal agencies must address it by 2026-09-27. Public exploit code is available.

How to fix CVE-2026-71362

  1. Isolate or restrict internet exposure of Adobe Commerce and Magento instances until mitigations are applied.
  2. Follow Adobe's vendor guidance and mitigations immediately; if a patch is unavailable, implement recommended configuration hardening.
  3. Monitor logs and investigate anomalous admin or privilege-related activity for signs of compromise.
  4. Apply network-level controls (WAF, IP allowlists) to block exploit attempts where feasible and prioritize replacement or removal of affected deployments per CISA guidance.

Frequently asked questions

Is CVE-2026-71362 being actively exploited?

Yes; CISA added CVE-2026-71362 to its Known Exploited Vulnerabilities catalog on 2026-09-24 and public exploit code is available.

Which Adobe Commerce and Magento versions are affected by CVE-2026-71362?

Adobe Commerce 2.x (2.4.9-2026-jul and earlier in the listed branch), Adobe Commerce B2B 1.x (1.5.3-2026-jul and earlier in the listed branch), and Magento Open Source 2.x (2.4.9-2026-jul and earlier in the listed branch) are affected.

Is there a patch for CVE-2026-71362?

No vendor-fixed versions are listed in the supplied facts; follow Adobe's guidance for available mitigations until a patch is released.

Does CVE-2026-71362 require authentication?

No; the vulnerability can be exploited over the network without authentication or user interaction against affected Adobe Commerce and Magento releases.

References