ZeroDayAlert

CVE-2026-71362: Adobe Commerce and Magento Incorrect Authorization Vulnerability

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.

Adobe Commerce and Magento Added to KEV 2026-09-24 Federal due 2026-09-27 Known ransomware use

Required action — quoted from CISA

Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

Where this comes from. The identifier, product, dates and required action above are copied verbatim from the CISA Known Exploited Vulnerabilities catalog. The action plan below is written by an AI agent from that record and published automatically. AssurePort has not independently tested this vulnerability and makes no claim about whether any specific system is affected.

Who is affected

Adobe Commerce and Magento deployments are vulnerable to an incorrect authorisation flaw that could allow an attacker to gain elevated access to sensitive resources without triggering user interaction. The record does not specify which versions of Commerce or Magento are affected, nor does it detail whether on-premises, cloud-hosted, or both deployment models are in scope.

How to check whether this touches you

  • Search your infrastructure inventory for any instance of Adobe Commerce or Magento, noting deployment type (on-premises, cloud-hosted, or hybrid) and the organisation or team responsible for each.
  • Verify network reachability to any admin interfaces, API endpoints, or customer-facing portals by checking firewall rules and whether instances are exposed to untrusted networks or the internet.
  • Obtain the exact running version number from each deployment's administration panel, system logs, or package metadata; version fingerprints alone do not confirm absence of risk, since security patches are sometimes backported to earlier releases.

What to do

  1. Treat this as a high-priority remediation task under CISA BOD 26-04 guidelines; the federal remediation due date is 27 September 2026.
  2. Consult Adobe's official security advisory and patch documentation to determine which versions require updates and obtain the correct patch or upgrade path for each affected instance.
  3. For any instance you cannot patch immediately, restrict network access to the Commerce or Magento deployment—disable public internet exposure, require VPN or IP allowlisting for administrative functions, and consider taking the storefront offline if safe to do so.
  4. Enable and review access logs for any administrative actions, API calls, or privilege escalations dating back at least 90 days; focus on accounts with unexpected elevated permissions.
  5. If your deployment is cloud-hosted and the vendor cannot provide mitigations, follow BOD 26-04 guidance to either migrate to an unaffected service or discontinue use.
  6. Document your patching timeline and any interim mitigations in your audit trail; this supports compliance demonstration.

If you find you were exposed

Exploitation typically precedes public disclosure by weeks or months, so you should search logs retrospectively across your full retention period for signs of unauthorised access or privilege escalation. Check for unexpected admin account creation, API tokens issued to unknown consumers, changes to access control rules, and data exports or modifications occurring outside normal business windows. If log retention is shorter than 90 days, prioritise extending it immediately for future incidents.

Get these the morning they land.

One email, only when a vulnerability is newly confirmed as exploited — the CISA record plus our action plan. No more than one a day, and nothing on quiet days.

Knowing it exists is not the same as knowing you are exposed.

This page can tell you that CVE-2026-71362 is being exploited. It cannot tell you whether Commerce and Magento is running somewhere of yours that is reachable. That question is what a scan answers.

Check your own surface →