Skip to content
Critical Authorization Flaw in Adobe Commerce and Magento Exposed

Critical Authorization Flaw in Adobe Commerce and Magento Exposed

First seen 29 Sep 2026, 09:07 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 09:08 UTC
  • •CVE-2026-71362 allows unauthenticated account takeover in Adobe Commerce and Magento.
  • •Adobe released patches on August 11, 2026, to address critical vulnerabilities.
  • •CISA added CVE-2026-71362 to its KEV catalog on September 24, 2026, indicating active exploitation.

On August 11, 2026, Adobe released a security update addressing CVE-2026-71362, a critical Incorrect Authorization vulnerability in Adobe Commerce, Adobe Commerce B2B, and Magento Open Source. This flaw allows unauthenticated account takeover, enabling attackers to switch customer sessions without any user interaction, leading to unauthorized access to sensitive data. The vulnerability has a CVSS score of 9.1, indicating its severity. CISA added CVE-2026-71362 to its Known Exploited Vulnerabilities catalog on September 24, 2026, due to confirmed exploitation attempts. Adobe's advisory APSB26-92 also covers additional vulnerabilities, emphasizing the need for immediate patching. Affected versions include Adobe Commerce 2.4.7-p10 and earlier, among others. Merchants are urged to apply the isolated patches promptly to mitigate risks. As of September 25, 2026, Adobe had not confirmed the exploitation status of this vulnerability.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-08-06
CVE-2026-5430 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-11
Adobe releases security update
Adobe issued patches for CVE-2026-71362 and other vulnerabilities affecting Adobe Commerce and Magento.
Article 1
2026-09-07
CVE-2026-75650 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-24
CISA adds CVE-2026-71362 to KEV catalog
CISA confirmed exploitation attempts and set a due date for federal agencies to remediate the vulnerability.
Article 2
2026-09-25
Adobe not confirms exploitation status
As of this date, Adobe had not updated its advisory to confirm whether the vulnerability was actively exploited.
Article 2

More articles in this cluster (3)

Following this threat?

Track Adobe and CVE-2026-5430 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed