CISA adds Adobe Commerce CVE-2026-71362 to exploited-flaw catalog
CISA listed the critical Adobe Commerce flaw on September 24. Operators should check affected versions and apply Adobe's matching fix.
CISA added CVE-2026-71362 in Adobe Commerce and Magento Open Source to its Known Exploited Vulnerabilities catalog on September 24, 2026. Adobe classifies the incorrect-authorization flaw as critical and says exploitation requires no authentication. Sansec's patch analysis describes a customer-session switch to another account. Adobe lists affected and fixed version lines; store operators should check their installed version and apply the matching update. The catalog entry does not establish a victim count or a universal merchant patch deadline.