CVE-2026-71362 - Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
- Severity
- critical
- Product
- Adobe Commerce and Magento
- Published
- 2026-09-24
- EPSS
- 0.896
- CISA KEV
- Known exploited
- Ransomware
- Known campaign use
References and validation
- https://github.com/search?q=CVE-2026-71362&type=repositories
- https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-71362.yaml
- https://nvd.nist.gov/vuln/detail/CVE-2026-71362
Entries are refreshed from CISA KEV and FIRST EPSS. Validate applicability before testing.