CVE-2026-71362 is exploited; Adobe Commerce teams face a September 27 deadline

LinkLoot editorial cover.LinkLoot
LinkLoot editorial cover.LinkLoot
Tools & Apps

CISA added CVE-2026-71362 to its Known Exploited Vulnerabilities Catalog on September 24. Adobe Commerce, Commerce B2B, and Magento Open Source operators should patch to the fixed August builds by the September 27 federal remediation deadline.

CISA added CVE-2026-71362 to its Known Exploited Vulnerabilities Catalog on September 24, 2026. The flaw affects Adobe Commerce and Magento and can let an attacker gain elevated access to sensitive resources without user interaction. Federal civilian agencies have a September 27 remediation deadline; other operators should treat the listing as an urgent patching signal.

What CISA's KEV listing changes

CISA classifies the issue as an incorrect authorization vulnerability and records active exploitation, automated exploitation, and total technical impact in its associated vulnerability enrichment. The catalog entry says ransomware use is unknown and requires forensic triage. Those details describe the risk signal; they do not establish that every affected store has been compromised.

The catalog's required action is to follow vendor mitigations, assess internet exposure, and apply the applicable BOD 26-04 guidance. If mitigation is unavailable, CISA says organizations should discontinue use of the product. The September 27 date is the federal deadline in the catalog, not a claim that exploitation stops afterward.

Affected Adobe Commerce and Magento builds

The CVE record lists a critical CVSS 3.1 score of 9.1 with network attack vector, low complexity, no privileges required, and no user interaction. It identifies affected Adobe Commerce, Adobe Commerce B2B, and Magento Open Source release lines.

Concept illustration: Affected Adobe Commerce and Magento builds
AI-generated illustration

The record marks these August 2026 builds as unaffected: Adobe Commerce 2.4.9-2026-aug through 2.4.4-2026-aug, Adobe Commerce B2B 1.5.3-2026-aug through 1.3.3-2026-aug, and Magento Open Source 2.4.9-2026-aug through 2.4.6-2026-aug. Confirm the exact supported target and deployment path against Adobe's security bulletin before upgrading; the Adobe page was not available to this fetcher, so this article does not reproduce vendor-specific installation steps.

Practical response for store operators

  1. Inventory Commerce, Commerce B2B, and Magento Open Source installations, including internet-facing admin and API endpoints.
  2. Compare each version with the fixed August build listed in the CVE record and apply Adobe's current remediation guidance.
  3. Review authentication, authorization, admin, and application logs for unexpected access to sensitive resources. Preserve relevant evidence before cleanup.
  4. Treat exposed or unpatchable systems as an incident-risk decision: isolate them, restrict access, and escalate through the organization's response process.

The immediate milestone is September 27, 2026 for the CISA catalog deadline. The unresolved operational question is whether each deployment has been exploited; patching and targeted log review should proceed together.

Sources and methodology

This alert uses CISA's KEV entry as the primary source and the independent MITRE CVE record for affected versions, severity, and exploitation characteristics. The Adobe vendor advisory is linked from both records but was not separately counted as corroboration.

From reading to doing

Try the related loot

Give Any Model a Sandboxed Shell and File Workspace with OpenRouter

Open loot