HIGH CISA-KEV ACTIVELY EXPLOITED PoC
CVE-2026-71362
Adobe Commerce and Magento Incorrect Authorization Vulnerability
Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction.
Affected Products
- Adobe: Commerce and Magento
References
- https://nvd.nist.gov/vuln/detail/CVE-2026-71362
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
This high severity vulnerability was published on 2026-09-24 via CISA-KEV. ⚠ This vulnerability is in the CISA Known Exploited Vulnerabilities (KEV) catalog — it is being actively exploited in the wild. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 89.6% (top 0% of all CVEs by exploitation probability). Affected: Adobe: Commerce and Magento .
Risk Timeline
CVE Disclosed2026-09-24 · 1 day ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible
CISA KEV — Actively ExploitedU.S. federal agencies required to patch · confirmed threat-actor activity
Remediation Resources
vulnfeed aggregates 11568 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.