CVE-2026-71362

Published Aug 11, 2026

Last updated 9 days ago

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-71362 is an Incorrect Authorization vulnerability identified in Adobe Commerce and Magento Open Source. This flaw allows for privilege escalation, meaning an attacker could gain elevated access to sensitive resources. Exploitation of this vulnerability does not require user interaction. Some reports indicate that this could enable an attacker to switch a customer's active account session to another, thereby gaining access to the victim's account and private data.

Description
Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. An attacker could leverage this vulnerability to gain elevated access to sensitive resources. Exploitation of this issue does not require user interaction.
Source
psirt@adobe.com
NVD status
Analyzed
Products
commerce, commerce_b2b, magento

Risk scores

CVSS 3.1

Type
Secondary
Base score
9.1
Impact score
5.2
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Exploit added on
Sep 24, 2026
Exploit action due
Sep 27, 2026
Required action
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Weaknesses

psirt@adobe.com
CWE-863

Social media

Hype score
Not currently trending
  1. 🚨 #ALERT — ADOBE COMMERCE / MAGENTO CVE-2026-71362 CONFIRMED ACTIVELY EXPLOITED September 24, 2026 — CISA added CVE-2026-71362 to the Known Exploited Vulnerabilities catalog, confirming exploitation in the wild. DISCLOSED BY: Adobe CONFIRMED EXPLOITED BY: CISA PRODUCT:

    @Python_s_

    27 Sept 2026

    59 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    1 Reply

    0 Quotes

  2. CISA added two actively exploited bugs to its KEV catalog, patch deadline today. WSO2 API Manager (CVE-2026-5430): path traversal to RCE. Adobe Commerce/Magento (CVE-2026-71362): account takeover, no login needed. Patch now if you run either. https://t.co/odmR2nhSvE

    @NoDramaCyber

    27 Sept 2026

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. 🟠 𝗛𝗜𝗚𝗛 · 𝗗𝗶𝘀𝗰𝘂𝘀𝘀𝗶𝗼𝗻 🧩 Products: 𝗪𝗦𝗢𝟮 𝗔𝗣𝗜 𝗠𝗮𝗻𝗮𝗴𝗲𝗿, 𝗔𝗱𝗼𝗯𝗲 𝗖𝗼𝗺𝗺𝗲𝗿𝗰𝗲, 𝗠𝗶𝗰𝗿𝗼𝘀𝗼𝗳𝘁 𝗦𝗵𝗮𝗿𝗲𝗣𝗼𝗶𝗻𝘁 🛡

    @intels_daily

    26 Sept 2026

    122 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. CISA added two actively exploited flaws to its KEV catalog: a WSO2 API Manager JWT bypass (CVE-2026-5430, CVSS up to 10.0) and an Adobe Commerce/Magento auth bypass (CVE-2026-71362, CVSS 9.1). Patches have been out since spring and August - if you run either product, check your

    @NoDramaCyber

    26 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CISA flags CVE-2026-5430 (WSO2) & CVE-2026-71362 (Adobe Commerce) as actively exploited – urgent patching needed to stop session‑hijack attacks on federal apps. #ThreatIntel #CyberSecurity https://t.co/0Rfr8lhlqS

    @Npj8448

    26 Sept 2026

    49 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. CISA added two actively exploited flaws to KEV: WSO2 CVE-2026-5430 (path traversal → RCE) and Adobe Commerce/Magento CVE-2026-71362. Federal deadline: Sept 27. Source: CISA + The Hacker News. Verify independently. #CyberSecurity #InfoSec #CVE #ThreatIntel #KEV

    @ThreatAlis

    26 Sept 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. TRC analysis shows attackers exploiting critical authentication bypass vulnerabilities in WSO2 API Manager (CVE-2026-5430) and Adobe Commerce (CVE-2026-71362) to compromise administrative accounts across banking and government sectors. Runtime segmentation helps limit blast

    @aviatrixtrc

    26 Sept 2026

    64 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CTI ALERT | Sept 25, 2026: CISA adds WSO2 (CVE-2026-5430) & Adobe Commerce (CVE-2026-71362) to KEV following active in-the-wild exploitation. ​Threat actors are targeting identity/API management & e-commerce sessions. ​More in comments ⬇️ #Cybersecurity #Thre

    @ThreatIntebzqf

    25 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. CISA KEV yesterday: WSO2 CVE-2026-5430 + Magento CVE-2026-71362. Active exploit. Due Sep 27. WSO2: JWT auth bypass. Magento: unauth privilege escalation / session hijack. Run either? Patch now, then check for prior compromise. https://t.co/go2sKcueBY

    @bluefortit

    25 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CISA added CVE-2026-5430 (WSO2 CVSS 10.0 auth bypass) and CVE-2026-71362 (Adobe Commerce session hijack) to its KEV catalog under active exploitation. Patch perimeter assets immediately. Intel to https://t.co/MKs4bJKzie https://t.co/QC14eBVf0C

    @2Workly

    25 Sept 2026

    1 Impression

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. CISA added two actively exploited flaws to KEV: CVE-2026-5430 (WSO2 RCE) and CVE-2026-71362 (Adobe Commerce session hijack). Audit edge instances and patch now. Details: https://t.co/KQCYKm2f5S Intel to enforcement: https://t.co/QC14eBVf0C #2workly

    @2Workly

    25 Sept 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. #CISA 🔴 CISA añade fallos críticos de WSO2 y Adobe Commerce al catálogo KEV por explotación activa. ⚠️ Las vulnerabilidades CVE-2026-5430 y CVE-2026-71362 afectan a identidad y comercio. Las agencias deben parchar ya. https://t.co/V80X32YJnb via #TheHackerNews

    @renodevv

    25 Sept 2026

    2 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  13. 【CISA KEV速報】2026-09-24付けで2件追加 ・CVE-2026-5430 WSO2 Multiple Products ・CVE-2026-71362 Adobe Commerce and Magento いずれも悪用確認済み。概要と対応期限はこちら https://t.co/um1SUocVPu

    @sec_news_com

    25 Sept 2026

    52 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CISA adds CVE-2026-71362 (@Adobe Commerce/Magento privilege escalation) and CVE-2026-5430 (WSO2 JWT bypass leading to RCE) to the KEV catalog after confirmed exploitation. Adobe issued guidance in August; WSO2 warned in May. Federal agencies must patch and investigate

    @WorldCyberNewsX

    25 Sept 2026

    18 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. 🚨 CISA KEV — ADOBE COMMERCE / MAGENTO CVE-2026-71362 (INCORRECT AUTHORIZATION → PRIVILEGE ESCALATION) CISA added CVE-2026-71362 to its Known Exploited Vulnerabilities (KEV) Catalog on September 24, 2026, based on evidence of active exploitation. Product: Adobe Commerce a

    @DailyDarkWeb

    25 Sept 2026

    4215 Impressions

    2 Retweets

    8 Likes

    2 Bookmarks

    3 Replies

    0 Quotes

  16. CISA Adds Two Known Exploited Vulnerabilities to Catalog(CISA、悪用確認済み脆弱性2件をKEVカタログに追加) #CISA (Sep 24) CVE-2026-5430 WSO2 複数製品パストラバーサル脆弱性 CVE-2026-71362 Adob​​e CommerceおよびMagentoの認証エラ

    @foxbook

    25 Sept 2026

    204 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  17. 🔒 #CyberSecurity CVE-2026-5430 & CVE-2026-71362: CISA KEV Adds WSO2 Path Traversal and Adobe Com… "On September 24, 2026, CISA added two vulnerabilities to its Known Exploited…" 🔗 https://t.co/QSj0aOrfug #CyberSecurity #ThreatIntel #cve #zeroday #patchtuesday

    @SecurityAr58409

    25 Sept 2026

    62 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. 米国サイバーセキュリティ・社会基盤安全保障庁(CISA)の既知の悪用された脆弱性カタログにWSO2複数製品のCVE-2026-5430とAdobe Commerce/MagentoのCVE-2026-71362を追加。対処期限は3日後の9/27。ランサムウェアによる悪用は

    @__kokumoto

    25 Sept 2026

    574 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  19. 🚨 CVE-2026-71362 (CVSS 9.1): Adobe Commerce account takeover exploited in the wild - PoC public Critical Vulnerability Alert! Adobe Commerce / Magento Open Source is affected by CVE-2026-71362. 🔍 Identify Targets via ZoomEye: Search Dork: app="Magento" Exposure: 132.1k h

    @zoomeyebot

    5 Sept 2026

    11 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  20. CVE-2026-71362 Exploited: Adobe Commerce Takeover - https://t.co/RmPGksG3ie

    @moton

    28 Aug 2026

    39 Impressions

    0 Retweets

    0 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  21. 🚨 August 20, 2026 Patches: CISA orders patching of 3 critical flaws by August 21. - Microsoft IKE (CVE-2026-33824, CVSS 9.8) - Adobe Commerce (CVE-2026-71362 CVSS 9.8) - SharePoint (CVE-2026-55040, CVSS 9.1) https://t.co/fR71dyoG2H | #CyberSafeUG #CERTUGCC https://t.co/86S

    @CERT_UG

    20 Aug 2026

    103 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  22. Adobe Commerce/Magento critical flaw CVE-2026-71362 is actively exploited, letting attackers hijack customer accounts. Patch now to secure data. #adobecommerce #magento #cve #sessionhijacking

    @mergenewsapp

    14 Aug 2026

    28 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  23. Adobe CommerceとMagentoに、認証なしで他の顧客アカウントへセッションを切り替えられる重大な脆弱性CVE-2026-71362が見つかり、悪用を試みる通信がすでに観測されている。攻撃者は既存アカウントや管理者権限、

    @yousukezan

    12 Aug 2026

    1239 Impressions

    0 Retweets

    2 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  24. ARETIQ Daily Vulnerability Bulletin — August 11, 2026 🔴 CRITICAL: CVE-2026-48362 (adobe/coldfusion_2025) AAS 13.8 🔴 CRITICAL: CVE-2026-71362 (adobe/adobe_commerce) AAS 13.8 — PoC available 🔴 CRITICAL: CVE-2026-72785 (craftcms/cms) AAS 13.5 — PoC available 🔴 CRI

    @AretiqAI

    11 Aug 2026

    897 Impressions

    1 Retweet

    9 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

Configurations