CVE-2026-71362: Adobe Commerce and Magento
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
- Vendor
- Adobe
- Product
- Commerce and Magento
- Vulnerability
- Adobe Commerce and Magento Incorrect Authorization Vulnerability
- Date added
- Sep 24, 2026
- CISA due date (U.S. federal agencies)
- Sep 27, 2026
- Known ransomware campaign use
- Unknown
- Weakness (CWE)
- CWE-863
References
This site summarizes CISA's catalog for information only. It is not security advice — follow your vendor's guidance and official advisories.
Last updated: · Catalog version 2026.10.02