CISA added Adobe's critical Commerce and Magento authorization bug to KEV 44 days after the August patch. Stores on July builds should patch and triage.
On 24 September 2026 CISA added CVE-2026-71362 to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is an incorrect authorization bug in Adobe Commerce, Adobe Commerce B2B and Magento Open Source. Adobe rates it 9.1 (Critical) and its bulletin marks it as needing no authentication and no admin privileges. Adobe fixed it on 11 August 2026 in bulletin APSB26-92, 44 days before the KEV listing. Any store still on a July 2026 or older build is exposed to a bug that CISA now lists as exploited.
What we know
Adobe describes the issue as an incorrect authorization vulnerability (CWE-863) that can lead to privilege escalation. NVD quotes the description: an attacker could "gain elevated access to sensitive resources," and exploitation does not require user interaction. The CVSS 3.1 vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N: network reachable, low complexity, high confidentiality and integrity impact, no availability impact. That score comes from Adobe; the NVD record carries no separate NIST score.
CISA's KEV entry is titled "Adobe Commerce and Magento Incorrect Authorization Vulnerability." It set a federal remediation due date of 27 September 2026, which has already passed. The entry flags forensic triage as required, and lists known ransomware campaign use as "Unknown." The CISA coordinator's SSVC assessment in the NVD record reads exploitation "active," automatable "yes," technical impact "total."
Adobe's bulletin, in the version we reviewed (last updated 18 August), still says Adobe is not aware of any exploits in the wild. That statement predates the KEV listing and should not be read as current. KEV is our evidence of exploitation.
We found no public technical write-up. The NVD references list only the Adobe bulletin and the CISA catalog entry. We do not know the vulnerable endpoint, the exploit path, who is exploiting it, or what attackers do afterward. We have seen no confirmed report of payment skimmers or any other specific payload tied to this CVE, and none is claimed here.
Who is affected
Adobe lists these as affected, at the July 2026 release or earlier:
- Adobe Commerce: 2.4.9, 2.4.8, 2.4.7, 2.4.6, 2.4.5 and 2.4.4.
- Adobe Commerce B2B: 1.5.3, 1.5.2, 1.4.2, 1.3.4 and 1.3.3.
- Magento Open Source: 2.4.9, 2.4.8, 2.4.7 and 2.4.6.
Fixed releases carry the -2026-aug suffix on each of those lines, for example 2.4.9-2026-aug and B2B 1.5.3-2026-aug. NVD records affected versions as CPE patch levels (such as 2.4.8 through p5), which does not map cleanly onto Adobe's date-suffixed builds; use Adobe's bulletin as the reference.
The same bulletin fixes six other CVEs: CVE-2026-48411 through CVE-2026-48416. Among them, CVE-2026-48416 (incorrect authorization, CVSS 7.5) is also marked as not needing authentication. Adobe credits researcher 0x0.eth for CVE-2026-71362. We have no evidence that any of the other CVEs is exploited.
What defenders should do
- Patch to the August 2026 release or later for your line, and for B2B if you run it. This is the vendor fix.
- Treat unpatched stores as possibly compromised. The KEV entry calls for forensic triage. Because the exploit path is unpublished, you cannot rule out exposure by looking for a known indicator. Review admin and API account creation, role and permission changes, and access to sensitive data since 11 August, and preserve logs before rebuilding anything.
- Check the date you patched. CISA does not say when exploitation began, so it may predate the patch. Any store that ran a July build on or after 11 August should be in scope for triage, and earlier logs are worth reviewing too.
- Inventory every instance, including staging environments and the B2B module, which has its own fixed versions.
If you find compromise, the post-exploitation cleanup steps in our CosmicSting eviction guide are a useful checklist for a different Magento flaw. It is not evidence about this one.
Sources
- Adobe, APSB26-92: https://helpx.adobe.com/security/products/magento/apsb26-92.html
- NVD, CVE-2026-71362: https://nvd.nist.gov/vuln/detail/CVE-2026-71362
- NVD API record: https://services.nvd.nist.gov/rest/json/cves/2.0?cveId=CVE-2026-71362
- CISA Known Exploited Vulnerabilities catalog: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json