Response · NEW YORK
CISA Adds Adobe Commerce Magento Auth Flaw CVE-2026-71362 to KEV
By Noah Park, Response, New York

NEW YORK - The Cybersecurity and Infrastructure Security Agency on September 24, 2026, added CVE-2026-71362 to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation against Adobe Commerce and Magento. Federal civilian agencies face a remediation due date of September 27, 2026, under Binding Operational Directive 26-04. CISA also flags forensic triage for this entry. Known ransomware campaign use is listed as Unknown.
Adobe documented the issue in security bulletin APSB26-92, published August 11, 2026, and last updated August 18, 2026. The bulletin lists Incorrect Authorization (CWE-863) with privilege-escalation impact, Critical severity, no authentication required, no administrator privileges required, and a CVSS 3.1 base score of 9.1 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N). Adobe's August bulletin stated the company was not aware of exploits in the wild for the issues addressed in that update. CISA's September 24 KEV addition is the later operational signal that active exploitation evidence now meets catalog criteria.
Affected lines named in APSB26-92 include Adobe Commerce 2.4.9-2026-jul and earlier through 2.4.4-2026-jul and earlier, Adobe Commerce B2B 1.5.3-2026-jul and earlier through 1.3.3-2026-jul and earlier, and Magento Open Source 2.4.9-2026-jul and earlier through 2.4.6-2026-jul and earlier. Adobe's solution table points operators to the corresponding -2026-aug builds for each line and rates the update Priority 2. Adobe credits 0x0.eth (0x0doteth) for reporting CVE-2026-71362.
For security operations and incident response teams, treat internet-reachable Adobe Commerce and Magento storefronts that remain on -2026-jul or earlier builds as a customer-session and data-exposure case. Priority work is inventory of Commerce, Commerce B2B, and Magento Open Source versions, confirmation that APSB26-92 -2026-aug builds are applied, review of customer authentication and session logs for anomalous account switches around the exploitation window, invalidation of active customer sessions after patching, and preservation of evidence before rebuilding any storefront that may have served elevated sessions. WAF coverage on customer and session endpoints is a compensating control, not a substitute for the vendor update.
- Primary CISA alert https://www.cisa.gov/news-events/alerts/2026/09/24/cisa-adds-two-known-exploited-vulnerabilities-catalog
- Adobe APSB26-92 https://helpx.adobe.com/security/products/magento/apsb26-92.html
- The Hacker News (Sep 25, 2026) https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html
- Sansec / SecurityAffairs context https://securityaffairs.com/197149/hacking/adobe-commerce-cve-2026-71362-comes-under-attack-shortly-after-public-disclosure.html
Noah Park is a Response correspondent covering incident response and blue-team containment for SOCtember, based in New York.