Skip to content
CISA Known Exploited Vulnerability

CVE-2026-71362 — Magento Actively Exploited CVE

Adobe Commerce and Magento contains an incorrect authorization vulnerability that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user

⚠ Actively exploited (CISA KEV) Magento 2026
CISA catalog entry
Product
Commerce and Magento
Vendor
Adobe
Added to KEV
2026-09-24
Remediation due
2026-09-27