Junglewise Threat Intelligence

CVE-2026-71362: Adobe Commerce and Magento incorrect authorization

CVE-2026-71362 · Severity: critical · Exploited in the wild · Published 2026-09-24

Executive brief

Adobe Commerce and Magento are e-commerce platforms used by businesses to build and manage online stores. This vulnerability allows an attacker to bypass authorization controls and gain elevated access to sensitive administrative resources without needing user interaction. An exploit could enable unauthorized account takeover, data theft, or modification of products and orders.

Technical details

This vulnerability is an incorrect authorization flaw in Adobe Commerce and Magento that allows attackers to bypass access controls and obtain elevated privileges. The vulnerability does not require user interaction, meaning an attacker can exploit it directly against vulnerable instances. The attack vector is network-based, suggesting the flaw is reachable remotely. The vulnerability has been actively exploited in the wild, indicating real-world attack campaigns are targeting affected systems. Patches should be applied immediately to all affected Commerce and Magento installations.

Affected products

  • Adobe Adobe Commerce
  • Adobe Magento

Timeline

  • 2026-09-24: disclosed
  • 2026-09-24: exploited

Related threats